Impact
A crafted HTML page exploits an inappropriate input handling routine in Google Chrome for Android, exposing weaknesses identified as CWE‑346 and CWE‑653. This flaw enables an attacker who has already compromised the renderer process to bypass the browser’s site isolation safeguards.
Affected Systems
The flaw exists in Google Chrome for Android versions prior to 148.0.7778.216. Devices running any earlier version are susceptible until the next update is installed.
Risk and Exploitability
It is not stated whether a public exploit has been disclosed, and the EPSS score is below 1%, indicating very low observed exploitation probability. The vulnerability is not listed in CISA KEV. However, it requires the attacker to first gain control of the renderer process, which could occur through other browser or system weaknesses. Once that condition is met, bypassing site isolation offers significant opportunities for further attacks within the browser session. The CVSS score of 5 reflects a moderate impact for an affected user.
OpenCVE Enrichment
Debian DSA