Impact
Insufficient policy enforcement in the Chrome WebView component on Android allows an attacker to bypass otherwise restricted navigation by delivering a crafted HTML page. This weakness, categorized as CWE-602 (Assertion) and CWE-807 (Improper Access Control), could enable a malicious web resource to trigger unintended navigation or content loading within a WebView, potentially facilitating phishing, click‑jacking, or other client‑side attacks.
Affected Systems
Any Android device running Google Chrome prior to version 151.0.7922.72 is affected. The flaw arises in the WebView implementation used by Chrome, so any application that embeds this component and relies on the browser’s navigation controls is vulnerable until the update is applied.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the medium severity range, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker serving a crafted HTML page that the victim’s device loads into a Chrome WebView, thereby bypassing navigation restrictions. Exploitation would require the victim to interact with the malicious page or for an application to load content from an attacker‑controlled source.
OpenCVE Enrichment
Debian DLA
Debian DSA