Impact
Google Chrome for Android contains an NFC handling issue that allows a remote attacker who has compromised the renderer process to leak cross‑origin data through a crafted HTML page. The flaw is rated moderate in severity as defined by Chromium security. This leak enables the attacker to read content that should be protected by the same‑origin policy, exposing user data or locally stored web content.
Affected Systems
Android devices running the Google Chrome stable channel with versions earlier than 150.0.7871.47 are vulnerable. The vulnerability applies to all Chrome installations on those devices until an update is applied.
Risk and Exploitability
A CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% implies a low likelihood of exploitation at present. The flaw requires the attacker to first gain control of a renderer process, which typically occurs via another vulnerability. Because the issue is not listed in the CISA KEV catalog, no widespread attacks have been reported. Nonetheless, with renderer compromise the attacker could retrieve cross‑origin data via a crafted page.
OpenCVE Enrichment
Debian DLA
Debian DSA