Impact
The flaw is an inappropriate implementation of WebAPKs in Google Chrome on Android before version 149.0.7827.53 that allows a remote attacker to craft a WebAPK that masquerades as a different domain. This domain spoofing can trick users into trusting malicious content, potentially enabling phishing, credential theft, or other attacks that compromise the integrity of web interactions. The weakness represents an improper authorization scenario where the domain identity is not properly validated.
Affected Systems
All users running Google Chrome on Android that are on a version earlier than 149.0.7827.53, regardless of device manufacturer, are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating medium overall severity. Its EPSS score is less than 1%, showing a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver a malicious WebAPK, generally through a WebAPK store or out-of-band installation. The limited exploitation probability and absence from KEV suggest that current exposure is low, but a successful attack could still allow domain spoofing and related phishing or credential‑stealing attacks.
OpenCVE Enrichment
Debian DSA