Impact
This vulnerability arises from insufficient policy enforcement within the NFC component of Google Chrome on Android. A remote adversary can craft a malicious HTML page that, when accessed by a victim, causes Chrome to expose cross‑origin data that should have been restricted. The primary impact is the disclosure of sensitive information that crosses site boundaries, potentially revealing user data or internal application state.
Affected Systems
Google Chrome for Android is affected. Specifically versions prior to 151.0.7922.72 are vulnerable. The threat targets Android devices running these legacy Chrome releases.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑severity issue, and the EPSS score of less than 1% suggests that exploitation is considered unlikely at present. The vulnerability is not listed in the CISA KEV catalog. A remote attacker would need to deliver a crafted HTML page to the target device, implying a web‑based attack vector. No specific prerequisites beyond a user accessing the malicious content are stated, so the attack is feasible if the victim visits a malicious or phishing site.
OpenCVE Enrichment
Debian DLA
Debian DSA