Impact
The vulnerability involves insufficient validation of untrusted input in the TabSwitcher component of Google Chrome on Android. A remote attacker who can send crafted network traffic to the device may cause the browser to bypass its navigation restrictions, exploiting a CWE-20 weakness. The impact is limited to overriding navigation controls and does not provide remote code execution or other higher‑level privilege escalation.
Affected Systems
Chrome on Android versions earlier than 150.0.7871.47 are affected. Users should confirm that their browser is at least this version or newer to avoid the issue.
Risk and Exploitability
With a CVSS score of 4.3 and an EPSS probability of less than 1%, the vulnerability is classified as low severity and is not listed in the CISA KEV catalog. It is inferred that the attacker must deliver malicious network traffic to the victim’s device, for example through a compromised local Wi‑Fi network or a malicious access point, in order to exploit the weakness. While the risk is low, the ability to bypass navigation safeguards could be used by adversaries who already have network access to a target device.
OpenCVE Enrichment
Debian DLA
Debian DSA