Impact
Google Chrome for Android contained an incorrect authorization check in the WebAppInstalls component that allowed a remote attacker to bypass system access restrictions. The flaw could be triggered by a crafted HTML page, enabling the attacker to install or interact with web applications with elevated privileges. The weakness is a classic lack of authorization (CWE-863).
Affected Systems
Android users running Google Chrome versions prior to 155.0.8059.39 are affected. The CVE documentation does not explicitly confirm that Chrome 155.0.8059.39 and later patched the issue, though it is probable that the release includes the fix.
Risk and Exploitability
The vulnerability can be exploited remotely via an attacker‑controlled web page presented to the user. EPSS data is not available and the issue is not listed in the CISA KEV catalog, yet Chromium formally rated the severity as Medium. Even without quantitative risk metrics, the potential for privilege escalation on a mobile device indicates that the vulnerability poses a non‑negligible threat, especially to users who frequently visit untrusted sites.
OpenCVE Enrichment