Impact
A race condition in Chrome’s Autofill component allows a remote attacker who already controls code execution in the renderer process to bypass the web origin policy through a specially crafted HTML page. This flaw, classified as CWE‑362, can cause data from one origin to be accessed by a different origin, compromising confidentiality and potentially allowing further exploitation within the browser’s context.
Affected Systems
Google Chrome users running versions earlier than 152.0.7977.65 are affected. The security advisory references the stable channel update for desktop browsers published in August 2026; all stable builds prior to the specified version inherit the vulnerability.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity. The EPSS score of <1% shows a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. The attack requires a pre‑existing compromise of the renderer process, so the vector is likely local or remote with elevated privileges. While the probability of exploitation remains low in the absence of a renderer compromise, the potential impact is significant because the flaw allows an attacker to bypass the web origin policy and access data from a different origin within the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA