Description
Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from an observable discrepancy in the Autofill functionality of Google Chrome. When a malicious web page is rendered, the Autofill mechanism can leak sensitive data that the user has stored, such as passwords or credit card details. This results in a remote disclosure of confidential information, exposing credentials and payment data, and the weakness maps to CWE-203, an issue where unauthorized data exposure occurs.

Affected Systems

All users of Google Chrome on any platform running a version earlier than 153.0.8010.36 are affected. The flaw applies to desktop releases on Windows, macOS, Linux, and other operating systems that ship with the core Chrome engine at or below that version.

Risk and Exploitability

An attacker can trigger the flaw by serving a specially crafted HTML page to a victim's Chrome browser; no local code execution or elevated privileges are required. The attack vector is inferred from the description and is remote. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, so the public exploitation likelihood is low. The CVSS score of 6.5 indicates medium severity, and the Chromium security severity is Medium, supporting the assessment that the vulnerability, while not highly severe, still warrants prompt remediation.

Generated by OpenCVE AI on September 9, 2026 at 16:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or newer to contain the fix.
  • Disable the Autofill feature in Chrome settings or enforce a group policy that blocks Autofill until the update can be applied.
  • Continuously monitor Chrome release notes and apply any subsequent security updates promptly.

Generated by OpenCVE AI on September 9, 2026 at 16:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Chrome Autofill Information Disclosure in Versions Prior to 153.0.8010.36

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Chrome Autofill Information Disclosure in Versions Prior to 153.0.8010.36

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T14:38:06.859Z

Reserved: 2026-09-08T22:38:13.638Z

Link: CVE-2026-87478

cve-icon Vulnrichment

Updated: 2026-09-09T14:35:52.931Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:04.437

Modified: 2026-09-09T17:14:57.603

Link: CVE-2026-87478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:30:13Z

Weaknesses