Impact
The vulnerability arises from inadequate validation of untrusted input within Chrome WebAPKs on Android. A locally present attacker could use a specially crafted file to escape the sandbox, potentially compromising the device. The flaw is a classic input validation issue, classified as CWE-20 and CWE-1286.
Affected Systems
This issue affects Google Chrome on Android versions prior to 151.0.7922.109. The known affected product is Google:Chrome.
Risk and Exploitability
Chromium rates the incident as high severity, with a CVSS score of 8.6. The exploitation requires local file access, so it is not remotely exploitable; any user who can place a malicious file on the device can trigger the exploit. The EPSS score is <1%, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. The exploitation path involves creating a malicious file and launching Chrome to process it.
OpenCVE Enrichment
Debian DLA
Debian DSA