Impact
Insufficient policy enforcement in DevTools within Google Chrome for Android prior to version 150.0.7871.47 permits a local attacker to open a malicious file and bypass navigation restrictions that the browser normally imposes. This flaw, identified as CWE-20, allows the browser to navigate to URLs or resources that it is supposed to block, providing an undesired pathway for the attacker to access potentially harmful content.
Affected Systems
All Android installations of Google Chrome older than version 150.0.7871.47 are vulnerable; devices that do not receive automatic updates remain at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while an EPSS score of less than 1% reflects a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a local attacker to place a crafted file on the device and a user to open that file in DevTools, confining the risk to local contexts and making remote exploitation unlikely.
OpenCVE Enrichment
Debian DLA
Debian DSA