Impact
An inappropriate implementation of the WebView component in Google Chrome on Android allows a remote attacker to present spoofed user interface elements through a crafted HTML page, potentially luring users into performing unintended actions. The weakness corresponds to input validation failures and unvalidated output handling, aligning with CWE‑1021 and CWE‑451.
Affected Systems
Google Chrome on Android versions earlier than 151.0.7922.72 are affected. Users running older Chrome releases that utilize the WebView component should be aware of this vulnerability.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk level, and the EPSS score of less than 1% suggests a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, requiring a victim to visit a malicious web page that exploits the WebView rendering path; exploitation requires user interaction with the spoofed UI and is not yet linked to publicly available tools.
OpenCVE Enrichment
Debian DLA
Debian DSA