Impact
The flaw involves improper authorization handling in Chrome’s Autofill feature on Android devices, which enables a crafted HTML page to retrieve data stored by the browser such as passwords, addresses, and credit card numbers. The vulnerability cannot be exploited for code execution or privilege escalation; it simply exposes confidential information to the attacker.
Affected Systems
Google Chrome on Android versions prior to 152.0.7977.75 is affected. Any device running a vulnerable version of Chrome that has Autofill enabled for saved form or payment data is potentially at risk.
Risk and Exploitability
The vulnerability requires a user to interact with a malicious page, making social engineering the primary attack vector. The EPSS score is not available and the issue is not listed in CISA KEV. The CVSS severity is low, indicating the flaw poses a low‑severity risk beyond data disclosure.
OpenCVE Enrichment