Impact
A crafted HTML page exploits an inappropriate input handling routine in Google Chrome for Android, exposing weaknesses identified as CWE‑284, CWE‑305, and CWE‑653. These flaws enable an attacker who has already compromised the renderer process to bypass the browser’s site isolation safeguards. The resulting privilege escalation permits the attacker to read, modify, or inject data across rendering contexts that are normally separated, creating a pathway to cross‑site data theft or credential compromise. Chromium classifies the vulnerability as High severity.
Affected Systems
The flaw exists in Google Chrome for Android versions prior to 148.0.7778.216. Devices running any earlier version are susceptible until the next update is installed.
Risk and Exploitability
No public exploit has been disclosed, and the EPSS score is below 1%, indicating very low observed exploitation probability. The vulnerability is not listed in CISA KEV. However, it requires the attacker to first gain control of the renderer process, which could occur through other browser or system weaknesses. Once that condition is met, bypassing site isolation offers significant opportunities for further attacks within the browser session. The CVSS score of 5.8 reflects a moderate‑to‑high impact for an affected user.
OpenCVE Enrichment