Impact
The vulnerability is caused by insufficient policy enforcement in the PDF handling subsystem of Google Chrome on Android before version 146.0.7680.71. As described in the vendor advisory, a crafted HTML page can trick the browser into bypassing navigation restrictions that are normally enforced for PDF files. This allows a remote attacker to force the browser to navigate to arbitrary URLs or trigger unintended actions, thereby enabling phishing, drive‑by downloads, or other malicious behaviors. The weakness is identified as CWE‑284, broken access control.
Affected Systems
Affected systems are Google Chrome browsers running on Android devices with versions earlier than 146.0.7680.71. No specific operating‑system versions are mentioned beyond the Chrome product itself; however the CVE entry lists CPEs for macOS, Linux, and Windows, indicating that the vulnerability is limited to the Android Chrome build.
Risk and Exploitability
The CVSS v3 score is 6.5, classifying the flaw as Medium severity. The EPSS score is reported as less than 1%, suggesting a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no confirmed exploitation activity. Based on the description, the likely attack vector is a remote, web‑based vector where the attacker hosts a malicious HTML page that opens a crafted PDF, thereby triggering the bypass. Exploitation requires the user to visit the malicious page and load the PDF, so the risk depends on user behavior.
OpenCVE Enrichment
Debian DSA