Impact
Inappropriate implementation of the QUIC protocol in Google Chrome on Android allows a remote attacker to leak cross‑origin data through a specially crafted HTML page. The flaw creates an information‑leak vector that can expose sensitive data belonging to a browsing user, potentially compromising privacy and data integrity without providing control over the device.
Affected Systems
Google Chrome on Android devices running versions prior to 151.0.7922.72. The vulnerability is tied to the Android implementation of the QUIC protocol and affects all users of the affected Chrome releases on mobile.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity impact, while an EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not present in the CISA KEV catalog. Attackers would need to serve a maliciously crafted HTML page to the victim’s Chrome browser; no privileged access or elevated rights are required, and the exploit would remain within the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA