Impact
A flaw in the WebXR implementation of Google Chrome on Android allows a remote attacker to craft an HTML page that, when opened in the browser, bypasses normal navigation restrictions. This enables the attacker to redirect the user to arbitrary URLs selected by the attacker, potentially facilitating phishing or social engineering. The vulnerability does not provide a path for arbitrary code execution, privilege escalation, or other more severe impacts.
Affected Systems
Android users who are running Google Chrome versions older than 150.0.7871.47 are potentially affected. The vulnerability is tied exclusively to the Google Chrome browser on Android devices running the vulnerable web platform component.
Risk and Exploitability
The CVSS score of 4.3 positions the flaw in the low severity range, and the EPSS score of less than 1 % indicates a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely exploit path involves a remote attacker serving a malicious HTML page that a user visits, triggering the navigation restriction bypass and enabling the attacker to direct the user to attacker‑controlled sites.
OpenCVE Enrichment
Debian DLA
Debian DSA