Impact
The vulnerability is an incorrect reference resolution bug in the Offline mode of Google Chrome on Android that can allow a remote attacker who has compromised the renderer process to retrieve sensitive information by serving a specially crafted HTML page. The weakness, identified as CWE-706, stems from improper validation of user-supplied URLs, which permits the renderer to access underlying references that should be protected. Once exploited, the attacker can read data that may be stored locally or otherwise considered confidential, resulting in a disclosure of private information.
Affected Systems
Affected products include Google Chrome for Android, specifically any build prior to version 155.0.8059.39. Users running older releases of Chrome on Android are vulnerable until the referenced update is installed.
Risk and Exploitability
The vulnerability’s severity is rated medium. Exploitation requires the attacker to first gain compromise of a renderer process, which typically means a malicious web page must be loaded or a preexisting vulnerability must be leveraged. Because the attacker must already control the renderer, the risk of spontaneous exploitation is limited, and the CVE is not listed in the CISA KEV catalog. No EPSS score is reported, so the public exploit probability cannot be quantified. The primary impact is data exposure through crafted HTML pages; no direct denial of service or remote code execution is possible.
OpenCVE Enrichment