Impact
The flaw arises from insufficient validation of untrusted input that passes through the Clipboard subsystem in Google Chrome for Android. A local attacker can create a malicious HTML page that reads clipboard entries and exposes data that may have originated from a different domain, leading to a confidentiality breach. The primary impact is cross‑origin data leakage, and the weakness is classified as an input‑validation error (CWE‑20) with source‑validation shortcomings (CWE‑346). Based on the description, the likely attack vector is a local attacker delivering the compromised HTML page through the device’s browser.
Affected Systems
Affected systems are all users running Google Chrome for Android version 151.0.7922.72 and earlier. The vulnerability applies across all device manufacturers and Android releases that ship with these Chrome versions, so any Android device with an obsolete Chrome install is at risk.
Risk and Exploitability
The CVSS score of 3.3 indicates medium severity, while the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying that there has been no widespread exploitation yet. A user would need to be on a device where a malicious page is loaded while clipboard data contains sensitive cross‑origin content; the attacker would then read that data without network privileges. The local nature of the attack limits its reach compared to remote code execution, but it can still compromise user privacy.
OpenCVE Enrichment
Debian DLA
Debian DSA