Impact
The flaw involves insufficient validation of untrusted input in WebAppInstalls on Android, which allows a local attacker to bypass discretionary access control. This weakness, classified as CWE-20, permits an attacker to elevate privileges by executing crafted HTML content within Chrome, leading to unauthorized data access and potential further compromise of device resources.
Affected Systems
Google Chrome on Android devices running any version prior to 150.0.7871.47 is affected. The vulnerability resides in the WebAppInstalls component of the Chrome browser.
Risk and Exploitability
The vulnerability can be exploited by a local attacker who can open a malicious HTML page within Chrome. The EPSS score is < 1%, while the CVSS score of 9.1 indicates high severity; the vulnerability is rated high in Chromium’s internal severity, indicating that exploitation is realistically possible and could lead to a local privilege escalation or broader access to protected resources. The flaw is not listed in the CISA KEV catalog, but its local nature and high severity warrant immediate patching.
OpenCVE Enrichment
Debian DLA
Debian DSA