Impact
Missing authorization controls in the Passwords component of Google Chrome for Android prior to version 155.0.8059.39 allow a remote attacker who has already compromised the renderer process to bypass the browser’s site isolation feature through a specifically crafted HTML page. This vulnerability represents a broken access control flaw (CWE‑862) and was assessed with a medium severity by Chromium. The impact of gaining access to isolated renderer contexts is the potential for cross‑site data leakage, theft of credentials or other sensitive information, and a possible escalation to more serious privileges if combined with other weaknesses.
Affected Systems
Versions of Google Chrome for Android earlier than 155.0.8059.39 are affected. Any device running those builds can be vulnerable to the bypass if a malicious renderer process is introduced into the browsing context.
Risk and Exploitability
The exploit requires the attacker to already compromise the renderer process, meaning lateral or initial access vector is a prerequisite. EPSS data is not available, and the issue is not listed in CISA KEV, implying that widespread exploitation has not yet been observed. However, because the vulnerability bypasses a core isolation mechanism, its potential impact is significant. The CVSS score indicates a medium severity, and the risk is heightened for environments that rely on site isolation for compartmentalizing sensitive web traffic.
OpenCVE Enrichment