Impact
Insufficient policy enforcement in the Chrome WebView component on Android before version 150.0.7871.47 allows a remote attacker to serve a crafted HTML page that tricks the WebView into navigating to URLs that were previously disallowed. This flaw, classified as CWE‑284 (Improper Authorization), results in unauthorized navigation and the possibility of loading malicious or unauthorized content without user consent, all without requiring local privileges.
Affected Systems
Google Chrome for Android versions older than 150.0.7871.47 are affected. Because the WebView component is often embedded in third‑party Android applications, the vulnerability can impact any app that utilizes this component.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1 % denotes a low likelihood of automated exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker‑crafted HTML page to be rendered by a WebView, which can occur through a malicious or compromised application or website. The attack is remote and does not require local privileges, but it can redirect users to malicious content.
OpenCVE Enrichment
Debian DLA
Debian DSA