Description
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw involves improper authorization handling in Chrome’s Autofill feature on Android devices, which enables a crafted HTML page to retrieve data stored by the browser such as passwords, addresses, and credit card numbers. The vulnerability cannot be exploited for code execution or privilege escalation; it simply exposes confidential information to the attacker.

Affected Systems

Google Chrome on Android versions prior to 152.0.7977.75 is affected. Any device running a vulnerable version of Chrome that has Autofill enabled for saved form or payment data is potentially at risk.

Risk and Exploitability

The vulnerability requires a user to interact with a malicious page, making social engineering the primary attack vector. The EPSS score is not available and the issue is not listed in CISA KEV. The CVSS severity is low, indicating the flaw poses a low‑severity risk beyond data disclosure.

Generated by OpenCVE AI on September 2, 2026 at 04:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.75 or a later release
  • Disable Autofill for saved form or payment data in Chrome settings if an update is not yet available
  • Educate users on the risks of opening suspicious web pages that request personal data

Generated by OpenCVE AI on September 2, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Chrome Android Autofill Authorization Bypass Exposing Sensitive Data

Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-01T23:42:29.663Z

Reserved: 2026-09-01T16:20:17.061Z

Link: CVE-2026-84327

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:27.557

Modified: 2026-09-02T00:18:27.557

Link: CVE-2026-84327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:45:17Z

Weaknesses