Impact
The vulnerability is a race condition in the CustomTabs component of Google Chrome for Android. A local attacker can exploit timing differences when a co‑installed app interacts with CustomTabs to trick Chrome into treating content from another origin as its own, effectively bypassing the web origin policy. This flaw, classified as CWE-367 and CWE-368, allows the attacker to read or modify data from trusted web origins without proper isolation.
Affected Systems
The affected product is Google Chrome for Android on devices running any version prior to 155.0.8059.39. The issue is limited to Android systems, and only users who have installed a malicious or compromised ancillary app that uses CustomTabs can be targeted.
Risk and Exploitability
The exploit requires local execution and a co‑installed app that can trigger the race. Because the attacker must be present on the device, the attack surface is limited to the victim’s device. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. However, Chrome assigns the issue a Chromium security severity of Medium, indicating that the potential impact is non‑trivial if a threat actor is capable of installing malicious applications on the target device. The CVSS score is 6.0.
OpenCVE Enrichment