Impact
The flaw stems from insufficient validation of untrusted input in Google Chrome for Android. An attacker who has already compromised the renderer process can deliver a crafted HTML page that forces the browser to display fabricated contents in the Omnibox, the URL bar. This enables the attacker to masquerade an arbitrary site as a legitimate one, potentially leading to phishing or credential theft. The weakness is associated with CWE‑20 (Improper Input Validation) and CWE‑290 (Improper Authentication). The impact is limited to UI manipulation rather than arbitrary code execution, giving the attacker influence over perceived destination URLs.
Affected Systems
The vulnerability affected Google Chrome for Android versions prior to 151.0.7922.72. The 151.0.7922.72 stable release contains the fix. Devices still running earlier Chrome releases are exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, while the EPSS score is less than 1 percent, implying a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires prior control of the renderer process, which restricts the attack surface. Nonetheless, if the renderer can be compromised through other vectors, an attacker could spoof URLs and deceive users. The moderate score, low exploitation likelihood, and absence from KEV suggest the overall risk is moderate, though ongoing monitoring is advisable.
OpenCVE Enrichment
Debian DLA
Debian DSA