Impact
An improper access control in the Sharing component of Google Chrome for Android allows a remote attacker who has already compromised the renderer process to deliver a crafted HTML page that forces the browser to expose data from other origins, thereby breaching confidentiality. The weakness involves CWE‑284 (Improper Authorization) and results in unauthorized disclosure of cross‑origin information.
Affected Systems
All installations of Google Chrome for Android that contain the vulnerable Sharing implementation, specifically versions prior to 150.0.7871.47, are potentially affected, regardless of the underlying Android platform.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 % reflects a low likelihood of widespread exploitation. Because the flaw requires the attacker to first compromise the renderer process, it is not trivially exploitable, but the potential for cross‑origin data leakage remains. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA