Impact
In Google Chrome on Android, a flaw in the renderer’s input handling lets a remote attacker who has already compromised the renderer process leak data from other origins using a crafted HTML page. The weakness is a data‑leak vulnerability and does not provide code execution or privilege escalation. The attacker gains unintended exposure to confidential information belonging to sites the renderer interacts with.
Affected Systems
Android devices running Google Chrome versions earlier than 150.0.7871.47 are affected. Vulnerability exists if a malicious HTML payload can reach the compromised renderer component.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability at a score of less than 1% indicates a very low likelihood of real‑world exploitation. It is not listed in CISA’s KEV catalogue. Exploitation requires prior compromise of the renderer process and delivery of a crafted HTML payload, so the practical risk to the average user is modest.
OpenCVE Enrichment
Debian DLA
Debian DSA