Impact
Insufficient validation of untrusted input in the Tab Group sync feature of Google Chrome for Android allows a remote attacker to inject arbitrary scripts or HTML content (UXSS). This flaw is identified as a medium‑severity vulnerability by Chromium and corresponds to the input‑validation error CWE‑20 and the displayed‑content error CWE‑79.
Affected Systems
All Chrome for Android installations that support Tab Group sync and are running versions older than 149.0.7827.53 are vulnerable. Devices with sync enabled and no patch applied are affected.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to craft malicious sync traffic; the flaw is remotely exploitable over network traffic and does not require additional user interaction. The likely attack vector is the sync traffic between the device and sync servers, inferred from the description that malicious network traffic is used to inject payloads.
OpenCVE Enrichment
Debian DSA