Impact
Insufficient validation of untrusted input in WebAppInstalls allows a local attacker to place a malicious file that can escape Chrome’s sandbox, potentially enabling arbitrary code execution or device compromise. The flaw carries a medium severity rating from Chromium security and is classified as CWE‑20, reflecting a lack of proper input validation.
Affected Systems
Google Chrome for Android versions prior to 150.0.7871.47 are affected. Devices running these builds can be compromised if a malicious file is introduced through the WebAppInstalls mechanism.
Risk and Exploitability
The vulnerability is local; an attacker must already have access to the device or be able to deliver a crafted file. No EPSS score is available and the flaw is not listed in CISA KEV, suggesting that exploit code may not yet be public, but the medium‑severity rating and sandbox escape potential mean that exploitation could have serious consequences. Updating Chrome to 150.0.7871.47 or later mitigates the risk promptly.
OpenCVE Enrichment