No milestones specified
Hi Yoav --Chrome web platform security folks took a quick look at this -- we think there aren't any concerns but I think the spec could be clarified a bit to make it more obviously the case :-)Section 6 flags that UAs SHOULD only expose the data after explicit user confirmation. We think this is also important irrespective of timing attacks.
It also wasn't immediately clear to us that the data being passed is limited to the specific autofill fields/type initially requested (and thus confirmed by the user) and this cannot be changed by the page handling the autofill event -- i.e., that all that can happen is a refill for the same data the user already consented to share. Maybe this is just under-specified and UA-dependent?
I think it would still be good to at least discuss in the Security/Privacy considerations section, even if it's non-normative.
Additionally, given that requirement, the new "full-address" field name may have UX challenges to ensure that the user understands the full scope of what is being shared.