Impact
This vulnerability arises from an inappropriate implementation within Cronet of Google Chrome on Android, allowing an attacker to craft domain names that spoof legitimate domains. The effect is that users could be misled to trust malicious websites that appear to be genuine, potentially leading to phishing, credential theft, or other social engineering attacks. The weakness aligns with domain spoofing issues that undermine the integrity and authenticity of the web browsing experience.
Affected Systems
Google Chrome for Android versions prior to 149.0.7827.53 are vulnerable. Any device running these older releases is at risk if an attacker can send a crafted domain to the browser for processing.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The EPSS score is less than 1%, signifying a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker supplying a specially constructed domain name to the affected browser instance; no local privilege escalation or code execution is described. Given the medium severity and low exploitation probability, the risk is moderate but should be mitigated promptly.
OpenCVE Enrichment
Debian DSA