Impact
An incorrect implementation in Google Chrome extensions on Android, prior to 150.0.7871.47, permits an attacker who convinces a user to install a malicious extension to bypass the same origin policy via a crafted Chrome Extension. This flaw, identified as CWE‑346 – Information Exposure Through an Insufficiently Isolated Extension, is rated high severity by Chromium and allows the extension to read or manipulate web content from other origins, potentially leaking confidential data or modifying site behavior.
Affected Systems
Google Chrome for Android versions earlier than 150.0.7871.47, including all Android builds shipping with Chrome below this patch level, are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no known public exploits. The most likely attack vector requires the victim to install a malicious extension, typically through social engineering or a compromised distribution; after installation, the extension can exploit the same origin policy bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA