Impact
A crafted HTML page can be served to a user of Google Chrome on Android, causing the browser to ignore the content security policy that normally prevents script execution. This lack of enforcement permits a remote attacker to inject and execute arbitrary JavaScript in the context of a website, which could lead to data theft, session hijacking, or additional compromise of the device. The vulnerability is rooted in an insufficient policy check during navigation and is categorized as a medium severity issue by Chromium security reviewers.
Affected Systems
Google Chrome for Android versions earlier than 149.0.7827.53 are affected. The flaw exists in the navigation handling subsystem and applies to all builds of Chrome for Android that have not yet implemented the policy enforcement fix. No other browsers or platforms are listed as affected.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not included in the CISA KEV catalog. Based on the CVSS score of 6.5, which denotes medium severity, the risk is considered medium. The likely attack vector is a remote attacker delivering a malicious web page to a user’s device; the attacker does not require any special permissions beyond typical web traffic. Exploitation would rely on the browser’s default behavior, so a user must visit a malicious site to trigger the bypass. The absence of publicly known exploit code suggests that the potential for XSS persists until the fix is deployed.
OpenCVE Enrichment
Debian DSA