Impact
An implementation flaw in Google Chrome’s NFC handling on Android allows a remote attacker to craft a malicious HTML page that can trigger privilege escalation. The vulnerability permits escaping Chrome’s sandbox, giving the attacker elevated privileges on the device. Chromium rates this issue as Medium severity. The flaw is based on inadequate access control (CWE-269) and a logical flaw that enables unauthorized behavior (CWE-648).
Affected Systems
The flaw affects installations of Google Chrome on Android running versions prior to 149.0.7827.53.
Risk and Exploitability
The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 8.8 indicates High severity. The flaw requires a crafted HTML page to be loaded in Chrome, implying the attack vector is via a malicious web page served over HTTP or HTTPS.
OpenCVE Enrichment
Debian DSA