Impact
Google Chrome for Android contains a vulnerability that can cause sensitive information to be exposed to a co‑installed application. A local attacker with control over a second app can retrieve data that should remain private to Chrome. This flaw is classified as medium severity and illustrates the risk of local information leakage inherent in poorly isolated app environments.
Affected Systems
The issue affects Google Chrome Mobile on Android devices running a version older than 155.0.8059.39. Only browsers built with the affected code prior to this patch are vulnerable.
Risk and Exploitability
The vulnerability is exploitable from the local device, requiring the attacker to install or control a second application. No exploit probability score is available, and the flaw is not listed in CISA KEV. The medium CVSS rating underscores the potential impact of confidential data exposure, while the absence of a publicly known exploit limits immediate risk. Updating to the patched Chrome version mitigates the principal threat.
OpenCVE Enrichment