Impact
The vulnerability is an inappropriate implementation in the Autofill feature of Google Chrome that allows a remote attacker to leak data from sites that the browser has accessed in previous sessions. By referencing stored form information from one origin in a malicious page loaded from another origin, an attacker can read and exfiltrate user data that was not intended for that site. This forms a cross‑origin data leakage flaw rather than an arbitrary code execution. The weakness is cataloged as CWE‑346, which represents an insecure handling of confidential data across origin boundaries.
Affected Systems
All installations of Google Chrome running a version older than 151.0.7922.72 are vulnerable. This includes the stable channel releases of Chrome for Windows, macOS, Linux, and possibly other supported platforms. Users who have not updated to at least the 151.0.7922.72 release are exposed.
Risk and Exploitability
The CVSS score is 4.3, indicating a medium impact when the flaw is exploited. The EPSS score is listed as < 1%, suggesting that, according to current data, the probability of exploitation in the wild is very low. Chrome is not currently listed in the CISA KEV catalog, and no public exploits have been widely reported. The likely attack path involves a victim visiting a malicious website that includes a specially crafted HTML page that triggers Autofill to supply previously saved data across origins. Because this does not require advanced privileges, the vulnerability is considered exploitable via a simply crafted web page, but its usefulness to attackers is limited by the narrow scope of the leakage and the need for user interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA