Impact
A defect in the browser logic of Google Chrome on Android permits a local attacker to construct a malicious HTML page that can read cross‑origin data that the page should not be able to access. The vulnerability is categorized as CWE‑346. No remote exploitation is possible; the attacker must already have local access to the device to craft the page that triggers the data leak. The impact is limited to privacy concerns and exposure of confidential information within the local context of the device.
Affected Systems
Google Chrome for Android on all versions preceding 151.0.7922.72 are vulnerable. Devices running Chrome 151.0.7922.72 or newer are unaffected.
Risk and Exploitability
The CVSS score of 3.3 reflects a low severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local attacker with physical or remote local access who serves a crafted page from the device to trigger the leak.
OpenCVE Enrichment
Debian DLA
Debian DSA