Impact
An insufficient policy enforcement bug in the Autofill feature of Google Chrome allows a remote attacker to provoke the browser to leak data that originates from another website. The flaw is triggered by a specially crafted HTML page and leads to an unintended data disclosure without granting code execution or system compromise. The vulnerability falls under the category of information exposure.
Affected Systems
Google Chrome versions earlier than 148.0.7778.96 are affected. Users running those releases are susceptible to this cross‑origin data leak. The issue has been documented by Google in their 2026‑05 stable channel update announcement and tracked in the Chromium issue tracker.
Risk and Exploitability
The CVE is rated with Chromium security severity Medium. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The attack requires an adversary to host a malicious page that the victim visits, so the exploitation is limited to a user’s browser. Despite the moderate risk, an attacker could harvest sensitive form data from other sites, which may be valuable for phishing or credential theft. The CVSS score of this vulnerability is 4.3.
OpenCVE Enrichment
Debian DSA