Description
Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an inappropriate implementation in the Autofill feature of Google Chrome that allows a remote attacker to leak data from sites that the browser has accessed in previous sessions. By referencing stored form information from one origin in a malicious page loaded from another origin, an attacker can read and exfiltrate user data that was not intended for that site. This forms a cross‑origin data leakage flaw rather than an arbitrary code execution. The weakness is cataloged as CWE‑346, which represents an insecure handling of confidential data across origin boundaries.

Affected Systems

All installations of Google Chrome running a version older than 151.0.7922.72 are vulnerable. This includes the stable channel releases of Chrome for Windows, macOS, Linux, and possibly other supported platforms. Users who have not updated to at least the 151.0.7922.72 release are exposed.

Risk and Exploitability

The CVSS score is 4.3, indicating a medium impact when the flaw is exploited. The EPSS score is listed as < 1%, suggesting that, according to current data, the probability of exploitation in the wild is very low. Chrome is not currently listed in the CISA KEV catalog, and no public exploits have been widely reported. The likely attack path involves a victim visiting a malicious website that includes a specially crafted HTML page that triggers Autofill to supply previously saved data across origins. Because this does not require advanced privileges, the vulnerability is considered exploitable via a simply crafted web page, but its usefulness to attackers is limited by the narrow scope of the leakage and the need for user interaction.

Generated by OpenCVE AI on August 3, 2026 at 11:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to a version equal to or newer than 151.0.7922.72, which contains a fix for the Autofill leakage flaw.
  • If an immediate upgrade is not possible, consider disabling the Autofill feature or restricting it to selected origins via the Chrome Flags interface (chrome://flags) to limit potential data exposure.
  • Monitor browser traffic for unexpected cross‑origin data requests from untrusted sites, and use network‑based security tools to block suspicious exfiltration attempts.

Generated by OpenCVE AI on August 3, 2026 at 11:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in Autofill
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T16:08:11.441Z

Reserved: 2026-07-27T23:35:10.727Z

Link: CVE-2026-17880

cve-icon Vulnrichment

Updated: 2026-07-30T13:23:31.517Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:51.940

Modified: 2026-08-03T17:37:15.330

Link: CVE-2026-17880

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:46Z

Links: CVE-2026-17880 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:00:16Z

Weaknesses