Impact
A flaw in Google Chrome for Android’s NFC handling permits a remote attacker to read data from a rendered HTML page; the vulnerability arises from improper validation of NFC data and insufficient origin checks, enabling cross‑origin information exposure. Based on the description, it is inferred that the attacker must first compromise the renderer process before exploiting this NFC flaw, as the attack path requires the renderer to be already compromised. Once the renderer is compromised, the attacker can leak potentially sensitive data from other web origins, which may affect confidentiality of user data that is normally protected by the same‑origin policy.
Affected Systems
All Android devices running Google Chrome stable channel version 150.0.7871.47 or earlier are affected if they have not applied the recent update. The issue applies to every instance of Chrome on those devices that has not yet been patched to the fixed release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% reflects a low current likelihood that exploitation will occur. Because the attack requires an initial compromise of the renderer—typically via a separate vulnerability—the overall risk remains moderate. The vulnerability is not listed in the CISA KEV catalog, further suggesting that it is not widely exploited at present. Nonetheless, a successful attacker who gains renderer access could obtain cross‑origin data that would otherwise be unavailable.
OpenCVE Enrichment
Debian DLA
Debian DSA