Impact
The issue is an insufficient policy enforcement flaw in the password subsystem of Google Chrome on Android. A crafted HTML page can exploit this weakness, allowing a remote attacker to bypass discretionary access controls and read or modify stored credentials. The vulnerability is classified as CWE‑1220 and CWE‑284, reflecting an access‑control weakness that grants unauthorized data access.
Affected Systems
All users running Google Chrome on Android with a build older than 151.0.7922.72 are vulnerable, as the flaw exists only in versions prior to that release.
Risk and Exploitability
The CVSS score of 6.5 signals a medium severity flaw. An EPSS score of < 1% indicates that exploitation is considered unlikely but not impossible. The CVE is not listed in CISA’s KEV catalog, suggesting no widespread attacks have been reported. The likely attack vector is a malicious HTML page that a user visits; no additional user interaction beyond normal browsing is required.
OpenCVE Enrichment
Debian DLA
Debian DSA