Impact
Chrome’s Autofill implementation on Android allows an attacker to load a crafted web page that presents a forged user‑interface element that looks like a Chrome form. This UI spoofing can convince a user to enter sensitive data, such as passwords or credit‑card details, under the false belief that it comes from the browser. The flaw maps to CWE‑451 and can compromise confidentiality and integrity of user‑supplied information.
Affected Systems
Google Chrome for Android versions prior to 150.0.7871.47 are affected. The vulnerability is limited to the Android platform and does not influence desktop or other operating‑system editions.
Risk and Exploitability
The bug can be triggered remotely by hosting a malicious page that a user visits. The likely requirement is that it operates without elevated privileges and depends on user interaction with the spoofed form. With a CVSS score of 4.3 and an EPSS lower than 1 %, the likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a web‑based interaction with a deceptive page.
OpenCVE Enrichment
Debian DLA
Debian DSA