Impact
An insufficient validation of untrusted input in Google Chrome on Android before 150.0.7871.47 allows a local attacker who can provide a malicious file to gain elevated privileges. The vulnerability, classified as a CWE‑20 input validation weakness, could enable an attacker to execute privileged actions on the device through the CustomTabs component.
Affected Systems
Google Chrome for Android versions earlier than 150.0.7871.47 are affected. The issue resides in builds that contain the CustomTabs component prior to the update.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, while the EPSS score of less than 1% indicates a low probability of exploitation. The flaw has not been listed in the CISA KEV catalog, and the likely attack vector is local; an attacker must be able to trigger CustomTabs with a malicious file via a link or file opening to achieve privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA