Impact
Improper input validation within Chrome’s Autofill component on Android allows a maliciously crafted web page to capture sensitive information from the user. The flaw can be abused by a remote attacker to exfiltrate confidential data within the context of an open browser session, potentially compromising user privacy. The vulnerability resides in the web engine’s handling of auto‑filled form fields and is classified as CWE‑20, a classic example of unsafe input validation.
Affected Systems
Google Chrome running on Android devices prior to version 152.0.7977.65 is affected. Any user with an out‑of‑date Chrome installation on Android can be exposed through browsing a malicious site.
Risk and Exploitability
Based on the description, it is inferred that a malicious web page can trigger the flaw by providing crafted input to the Autofill component. The CVSS score of 6.5 indicates medium severity, and the EPSS score is <1%, implying a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw can be exploited via a normal web page, any Chrome user could be targeted, with the impact of data leakage that could affect confidentiality. As the issue is remote and does not require local privileges, the exploitability is considered low in likelihood. Patches in versions 152.0.7977.65 and later have been released to fix the problem.
OpenCVE Enrichment
Debian DLA
Debian DSA