Impact
The flaw is a cross‑site request forgery in the ReadingList component of Chrome for Android. A crafted HTML page can force the browser to perform actions that bypass the web origin policy, allowing a remote attacker to send privileged requests on the user’s behalf. The vulnerability has a medium severity rating and could result in unauthorized data access or other malicious behavior.
Affected Systems
Affected versions are any Chrome for Android builds prior to 155.0.8059.39. The issue is specific to the Android platform and impacts all devices running Chrome before this update.
Risk and Exploitability
The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. The likely attack vector is social engineering, where a user must open a malicious webpage or click a link that triggers the ReadingList CSRF. Given the medium severity and absence of publicly known exploits, the immediate risk is moderate; however, users should still prioritize updating Chrome.
OpenCVE Enrichment