Impact
The vulnerability arises from insufficient validation of untrusted input in PDF viewing on Android Chrome versions prior to 151.0.7922.72. A local attacker could construct a crafted HTML page that triggers the PDF component, causing Chrome to expose cross‑origin data. The flaw permits an attacker to read any data that would otherwise be protected by same‑origin policy, effectively a local data leak. The weakness is an input validation issue (CWE‑20, CWE‑346).
Affected Systems
Google Chrome running on Android devices, specifically versions before 151.0.7922.72. The issue is present in all builds of the stable channel for Android that include the embedded PDF renderer.
Risk and Exploitability
The CVSS score of 6.5 classifies the impact as moderate. The EPSS score is below 1 %, indicating exploitation is expected to be rare. The flaw is not listed in CISA KEV. Attacks require a local user to open a crafted HTML page that contains an embedded PDF; the PDF viewer then yields cross‑origin data, so the attack vector is local access via a user‑initiated action. No remote code execution is provided by this flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA