Sceawere

Vulnerability Detail

CVE-2026-84327UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Autofill Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Incorrect authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-02T00:18:27.557Z",
  "pubdate": "2026-09-02T00:18:27.557Z",
  "executiveSummary": "This vulnerability involves an incorrect authorization flaw within the Autofill component of Google Chrome on Android, potentially allowing unauthorized data access.\nThe vulnerability is classified as an authorization bypass, which facilitates the unauthorized extraction of sensitive user information.\nAffected systems include Google Chrome on Android versions prior to 152.0.7977.75.\nThe risk implication is categorized as Low severity, primarily because the attack vector necessitates active user interaction via social engineering.\nA remote attacker can exploit this flaw by inducing a user to interact with a specifically crafted HTML page.\nUpon successful exploitation, the attacker could obtain sensitive data that the browser's Autofill feature is intended to protect, thereby compromising user privacy and data security.\nThe requirement for social engineering acts as a primary constraint, as the attacker cannot achieve unauthorized access solely through passive network activity without inducing user participation.",
  "technicalDetails": "The vulnerability resides within the Autofill service implementation in Google Chrome for Android. It stems from improper authorization checks during the interaction between the browser's Autofill engine and external contexts.\nThe root cause is an inadequate validation of the origin or context requesting autofill operations, allowing a malicious document to bypass standard security boundaries enforced by the browser's origin-based security model.\nThe exploitation method relies on the use of a crafted HTML page designed to mislead the user. By utilizing social engineering techniques, an attacker coerces the victim into interacting with this page, triggering the Autofill component under false pretenses.\nWhen the crafted HTML page is loaded, it initiates an interaction with the browser's Autofill framework. Due to the authorization flaw, the browser fails to correctly verify the legitimacy of the request, incorrectly assuming it originated from a trusted source or that the user has authorized the disclosure of sensitive information to the current context.\nThe attack flow follows these steps: 1. The attacker deploys a malicious HTML page. 2. A victim navigates to this page via social engineering vectors (e.g., phishing). 3. The page executes a script designed to invoke the browser's Autofill functionality. 4. Due to the authorization error, the browser's Autofill mechanism provides sensitive data to the attacker-controlled page, despite the page not being authorized to access that information.\nThe vulnerable component is the internal Autofill service management logic within Chrome on Android, specifically regarding how it handles cross-origin requests or context-switching during autofill triggering events.\nThis vulnerability does not require prior authentication to the application, as the entry point is external web content. However, the attacker must possess sufficient knowledge to engineer a convincing social engineering scenario.\nThe network exposure is broad, as any user browsing the internet with an affected version of Google Chrome on Android is susceptible to this attack if they can be lured to the malicious page.\nPost-exploitation impact involves the exfiltration of sensitive information, such as stored credentials, addresses, or payment details, which could lead to further unauthorized account access or fraudulent activities."
}
CVE-2026-84327: Google Chrome Autofill Authorization Bypass (MEDIUM Severity, CVSS: 6.5) - Sceawere