Impact
An incorrect authorization check in Google Chrome for Android enables an attacker who can co‑install an application and persuade a user to install it through social engineering to extract sensitive information from the browser. The flaw specifically allows the co‑installed app to bypass normal permission boundaries and read data that should be restricted to the browser process. This represents a medium‑severity source code issue identified as CWE‑863.
Affected Systems
The vulnerability exists in Google Chrome for Android versions earlier than 155.0.8059.39 and affects all devices that use these legacy releases. Users of older Chrome releases deployed on Android should consider this product impacted until they upgrade to a patched version.
Risk and Exploitability
The CVE is not listed in the CISA KEV catalog, and no EPSS score is available, which suggests limited publicly available exploitation data at this time. The CVSS base score of 5.1 indicates medium severity. Despite that, the potential for local privilege escalation via a co‑installed app is non‑trivial, especially in environments where users readily install unknown applications. The medium severity rating indicates a noticeable impact if exploited but not a critical or immediate denial of service. Patch status and user behavior remain the key determinants of risk.
OpenCVE Enrichment