Impact
A race condition in Google Chrome’s Picture‑in‑Picture feature on Android allows a remote attacker to serve a specially crafted HTML page that forces the browser to display a spoofed domain. The attacker can thus present a site that appears to belong to a legitimate domain, potentially enabling phishing or credential theft.
Affected Systems
The vulnerability affects Google Chrome for Android, specifically all releases prior to version 151.0.7922.72. Users running an earlier build are susceptible; newer releases include the fix.
Risk and Exploitability
With a CVSS score of 6.5 the issue is considered moderate severity. The EPSS score is under 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker hosting a malicious page that the victim visits or is exposed to via an open web session. Exploitation requires only the victim’s device to load the crafted HTML, making it a remotely exploitable web‑based technique.
OpenCVE Enrichment
Debian DLA
Debian DSA