Impact
An incorrect authorization check in the Search feature of Google Chrome on Android allows a remote attacker to supply a crafted HTML page that could bypass the browser sandbox and execute arbitrary code. The flaw is vulnerable to social engineering, as it requires a user to open or view the malicious content in Chrome. This abuse could compromise the confidentiality, integrity, and availability of the affected device.
Affected Systems
Versions of Google Chrome for Android older than 155.0.8059.39 are affected. The issue applies to any Android device running Chrome before this release, regardless of the device model or manufacturer.
Risk and Exploitability
The flaw has a CVSS score of 9.6, indicating a high severity risk. It is not listed in the CISA KEV catalog and, as EPSS is not available, the exploitation probability remains uncertain. However, the requirement for social engineering and user interaction still places it at moderate risk, making large‑scale deployment unlikely.
OpenCVE Enrichment