Impact
Insufficient validation of untrusted input in Chrome’s WebAppInstalls feature on Android constitutes a CWE‑20 input validation weakness. A local attacker can craft an HTML page to bypass discretionary access controls, potentially exercising unauthorized local privileges and escalating privileges on the device.
Affected Systems
The vulnerability affects Google Chrome on Android, specifically versions older than 150.0.7871.47. Only the Android build is listed; no mention of desktop versions in the description.
Risk and Exploitability
The CVSS score of 9.1 reflects a high severity level, and the EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have access to the device or be able to deliver the crafted HTML to the user, which implies the attacker has physical or local access. Exploitation would allow privilege escalation on the device, making the potential impact significant.
OpenCVE Enrichment
Debian DLA
Debian DSA