Impact
Insufficient validation of untrusted input in the WebAppInstalls component of Google Chrome for Android enables a local attacker to craft an HTML page that bypasses the browser's same-origin policy. The primary impact of this weakness is that an attacker can read or modify data belonging to a different origin within the device's browser context, potentially exposing sensitive information or executing arbitrary scripts. The flaw is a classic input validation error and is mapped to CWE-20.
Affected Systems
Google Chrome for Android, all releases prior to version 150.0.7871.115. The vulnerability is specific to the Chrome browser on Android and does not affect later releases or other platforms.
Risk and Exploitability
The3 indicates of less than 1 % suggests that exploitation is unlikely at present. No publicly documented exploitation has been reported. The attack requires local access to the device and the ability to serve or open a specially crafted HTML page. Although the flaw is categorized as \"High\" in Chromium's internal severity, the overall risk to a general user base remains low due to the local-only nature of the attack and the lack of widespread exploitation evidence.
OpenCVE Enrichment
Debian DLA
Debian DSA