Impact
Based on the description, it is inferred that Google Chrome for Android contains an insufficient validation of untrusted input when handling file input operations. This flaw allows an attacker to craft a malicious HTML page that, when opened by a user, can read data from a cross-origin source and leak that sensitive information. The weakness is an instance of improper input validation, represented by CWE-20.
Affected Systems
The issue affects all Android installations of Google Chrome running versions earlier than 150.0.7871.47, regardless of the device or Android OS version. Users who have not updated their browser to the 150.0.7871.47 stable channel or newer are at risk.
Risk and Exploitability
Chromium rates the vulnerability as medium-high severity (CVSS 6.5) and it is not listed in the KEV catalog. The EPSS score of < 1% indicates a low likelihood of exploitation. Based on the description, it is inferred that the attack requires a malicious or compromised web page that a user opens in the affected browser; a remote attacker can host such a page and force a victim to load it, enabling the attacker to read cross-origin data via the vulnerable file input handling.
OpenCVE Enrichment
Debian DLA
Debian DSA