Impact
The flaw emerges from an inappropriate CustomTabs feature, which permits a remote attacker to supply a crafted HTML page that CustomTabs will load. This actionorigin policy, potentially allowing access to or modification of web resources normally restricted. The weakness is identified as CWE‑346, a Same Origin Policy Bypass, which could let an attacker read or alter data within the victim’s browser session that is normally protected, though the overall impact is limited to content loaded via CustomTabs.
Affected Systems
Google Chrome for Android versions earlier than 150.0.7871.47 are affected. The issue is limited to the CustomTabs component and does not impact other parts of the browser.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low severity; the EPSS score of <1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a remote attacker delivering a specially crafted HTML page to a victim’s device, typically via a third‑party application that engages CustomTabs. While this vulnerability is confined to CustomTabs and does not affect the entire browser, the bypass of the same‑origin policy remains significant for the affected devices. Based on the description, it is inferred that the attacker can gain access to content that by the same‑origin restriction.
OpenCVE Enrichment
Debian DLA
Debian DSA