What happened
An observable-discrepancy (timing/UI) flaw in Chrome's Autofill AI feature (CWE-203) allowed a remote attacker who had already compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. Chromium severity: Medium. A companion low-severity improper-state-validation (CVE-2026-106343) allows UI spoofing on Android. Both fixed in the Oct 2026 stable desktop channel update.
Why it matters
Chrome's Autofill AI is an on-device AI feature that can surface and autofill saved personal data; this is defense-in-depth for AI-feature data handling but requires a prior renderer compromise, so standalone priority is low for AI deploys.
Attack vector
Crafted HTML page drives an observable discrepancy in Autofill AI after an attacker has already compromised the renderer process, exfiltrating sensitive autofill data.
Affected systems
Google Chrome prior to 155.0.8059.39 (desktop stable, Oct 2026)
Mitigation
Update Chrome to 155.0.8059.39 or later.