Impact
A remote attacker who has already compromised the renderer process can craft an HTML page that causes Chromium’s Autofill module to leak cross‑origin information. The vulnerability is a side‑channel flaw that does not allow arbitrary code execution or data modification, but it enables the disclosure of sensitive data from other origins. This flaw aligns with CWE-1300 and CWE-346. The weakness is classified as a medium severity issue in Chromium’s own severity taxonomy. The primary consequence is confidentiality loss for users who remain logged into websites while the leakage occurs.
Affected Systems
Google Chrome users running versions prior to 151.0.7922.72 are affected. The flaw exists in the default Autofill implementation shipped in the stable channel of Google Chrome. Users of later versions are not impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk, and an EPSS score of less than 1% shows a very low likelihood of exploitation. Because the flaw requires a renderer process to be compromised first, an attacker would need either a local foothold or a successful cross‑site process hijack. The vulnerability is not listed in the CISA KEV catalog, further suggesting that it is not currently widely exploited. Nonetheless, organizations that rely on Chrome for secure browsing should consider the possibility of cross‑origin data leakage from Autofill if an attacker gains access to a renderer process.
OpenCVE Enrichment
Debian DLA
Debian DSA