Impact
Improper input validation in the Omnibox component of Google Chrome on Android allowed an attacker to craft a malicious HTML page that, when visited, could bypass the browser’s web origin policy. This flaw enabled a remote attacker to potentially read or modify content from other origins that the user was authenticated to, thereby exposing confidential information or enabling further malicious actions. The flaw is identified as CWE‑20, indicating an input validation weakness. The Chromium security team rated the issue as High severity, reflecting the potential impact on user data and privacy.
Affected Systems
The vulnerability affects users of Google Chrome on Android using any version prior to 155.0.8059.39. No specific patch versions are listed, but any Android installation of Chrome before this release is susceptible.
Risk and Exploitability
The exploit requires social engineering; a malicious actor must persuade a user to visit a crafted page for the bypass to occur, implying user interaction. Because the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of exploitation is uncertain but not negligible. The high severity rating suggests a significant risk if exploited, and the cross-origin policy violation can lead to data leakage or unauthorized actions. No publicly documented zero‑day exploit exists as of the release note.
OpenCVE Enrichment