Impact
A flaw in the WebAppInstalls component of Google Chrome on Android allows a local attacker to place a malicious file that will be rendered as a legitimate user interface, enabling UI spoofing. The vulnerability is identified as CWE‑451 and is considered low‑severity by Chromium security, though the CVSS score of 7.5 indicates a high impact if exploited.
Affected Systems
All Android installations of Google Chrome running any build prior to 150.0.7871.47 are vulnerable, including every release of the Chrome stable channel that has not yet been updated to that specific build or later.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact if exploited, underscoring the severity of the flaw. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV. Exploitation requires local access to the device and the ability to place a malicious file, such as via a local file transfer or file‑manager action. Based on the description, it is inferred that no remote or privilege‑elevation path is needed and there is no evidence of widespread exploitation to date.
OpenCVE Enrichment
Debian DLA
Debian DSA