Impact
This vulnerability is a cryptographic flaw in the WebAppInstalls component of Google Chrome on Android. A specially crafted HTML page can trigger the flaw, allowing a local attacker to escape the browser sandbox and potentially execute code with higher privileges. The weakness is identified as CWE-1240 and CWE-347.
Affected Systems
Google Chrome for Android versions prior to 151.0.7922.72 are affected. Only the browser version is specified; no additional operating system or channel information is provided.
Risk and Exploitability
The CVSS score of 6.1 denotes a medium severity potential impact. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack requires a local or physical presence to place a malicious HTML page and trigger the flaw, but no public exploits are referenced in the CVE record.
OpenCVE Enrichment
Debian DLA
Debian DSA