Impact
The flaw involves improper authorization handling in Chrome’s Autofill feature on Android devices, which enables a crafted HTML page to retrieve data stored by the browser such as passwords, addresses, and credit card numbers. The vulnerability cannot be exploited for code execution or privilege escalation; it simply exposes confidential information to the attacker.
Affected Systems
Google Chrome on Android versions prior to 152.0.7977.75 is affected. Any device running a vulnerable version of Chrome that has Autofill enabled for saved form or payment data is potentially at risk.
Risk and Exploitability
The vulnerability requires a user to interact with a malicious page, making social engineering the primary attack vector. The EPSS score is not available and the issue is not listed in CISA KEV. The CVSS score of 6.5 indicates a medium‑severity risk beyond data disclosure.
OpenCVE Enrichment
Debian DLA
Debian DSA