Impact
Insufficient XML policy enforcement in Google Chrome on Android allows a remote attacker to obtain potentially sensitive information from the browser process memory via a crafted HTML page. The primary impact is the disclosure of confidential data due to a weakness in access control (CWE-284).
Affected Systems
Google Chrome on Android versions earlier than 150.0.7871.47 are affected.
Risk and Exploitability
Because the flaw page, an Android user who visits a compromised website can exploit the vulnerability without needing elevated privileges or additional steps. The CVSS score of 6.5 indicates moderate severity, the EPSS score of < 1 % suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA