Impact
The vulnerability arises from an inappropriate implementation in CustomTabs in Google Chrome on Android prior to version 150.0.7871.47, allowing a remote attacker to supply a crafted HTML page that CustomTabs will load. This bypasses the same origin policy, potentially permitting an attacker to read or modify data that is normally protected by that policy within the victim’s browser session. The weakness is identified as CWE-346, a Same Origin Policy Bypass, and the impact is limited to content loaded via CustomTabs.
Affected Systems
Google Chrome for Android versions earlier than 150.0.7871.47 are affected. The issue is limited to the CustomTabs component and does not impact other parts of the browser.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low severity; the EPSS score of <1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a remote attacker delivering a specially crafted HTML page to a victim’s device, typically via a third‑party application that engages CustomTabs. While this vulnerability is confined to CustomTabs and does not affect the entire browser, the bypass of the same‑origin policy remains significant for the affected devices. Based on the description, it is inferred that the attacker can gain access to content that by the same‑origin restriction.
OpenCVE Enrichment
Debian DLA
Debian DSA