Impact
A crafted HTML page can be served to a user of Google Chrome on Android, causing the browser to ignore the content security policy that normally prevents script execution. This lack of enforcement permits a remote attacker to inject and execute arbitrary JavaScript in the context of a website, which could lead to data theft, session hijacking, or additional compromise of the device. The vulnerability is rooted in an insufficient policy check during navigation and is categorized as a medium severity issue by Chromium security reviewers.
Affected Systems
Google Chrome for Android versions earlier than 149.0.7827.53 are affected. The flaw exists in the navigation handling subsystem and applies to all builds of Chrome for Android that have not yet implemented the policy enforcement fix. No other browsers or platforms are listed as affected.
Risk and Exploitability
No EPSS score is currently available, and the vulnerability is not included in the CISA KEV catalog. Based on the Chromium severity designation and the nature of the flaw, the risk is considered moderate. The likely attack vector is a remote attacker delivering a malicious web page to a user’s device; the attacker does not require any special permissions beyond typical web traffic. Exploitation would rely on the browser’s default behavior, so a user must visit a malicious site to trigger the bypass. The absence of publicly known exploit code suggests that the immediate threat is low to moderate, but the potential for XSS persists until the fix is deployed.
OpenCVE Enrichment