Impact
The vulnerability arises from insufficient policy enforcement within the Payments component of Google Chrome for Android prior to version 150.0.7871.47, allowing sensitive information from the browser’s process memory to be accessed, potentially exposing payment data and other confidential data. This weakness is identified as CWE-284: Improper Authorization, resulting in a breach of confidentiality.
Affected Systems
All users of Google Chrome for Android running a version older than 150.0.7871.47 are affected. The issue targets the native Payments API used by web applications within the browser.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as medium severity, and while no public exploit is currently documented, the attack vector is inferred to be a remote attacker serving a malicious HTML page while the victim’s browser is open. The EPSS indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a moderate chance of exploitation limited to environments where the attacker can influence content loaded by the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA