Impact
Inappropriate implementation in the Autofill component of Google Chrome on Android, before version 151.0.7922.72, permits a remote attacker to cause the browser to expose data from other origins through a specially crafted HTML page. The flaw is categorized as CWE‑346 and CWE‑940 and was considered medium severity by Chromium’s security team.
Affected Systems
All users of Google Chrome on Android running any build older than 151.0.7922.72 are affected. The issue specifically targets Android devices where the default Autofill behavior is enabled.
Risk and Exploitability
The listed CVSS score is 4.3, indicating moderate impact. The EPSS score is under 1 %, meaning exploitation probability is currently very low, and the flaw is not present in the CISA KEV catalog. The likely attack vector is a remote web page that the victim visits; the attacker must supply a crafted HTML payload that exploits the Autofill handling logic to read cross‑origin data.
OpenCVE Enrichment
Debian DLA
Debian DSA