Impact
An inappropriate implementation in the Sharing component of Google Chrome on Android allows a remote attacker who has already compromised the renderer process to supply a crafted HTML page that forces the browser to expose data originating from other websites, bypassing normal origin isolation boundaries. This results in confidential information disclosure. The weakness is an improper access control (CWE‑284).
Affected Systems
Google Chrome for Android prior to version 150.0.7871.47 is affected. The flaw exists on all Android device installations running those builds, regardless of the platform version.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1 % reflects a low likelihood of widespread exploitation. The vulnerability requires the attacker to first compromise the renderer process. The defect is not listed in the CISA KEV catalog. Prompt patching mitigates the cross‑origin data leakage risk.
OpenCVE Enrichment
Debian DLA
Debian DSA