Impact
An incorrect reference resolution (CWE-706) flaw in the Chrome Core module on Android allows a remote attacker to obtain sensitive information by social engineering through a crafted HTML page. The vulnerability is triggered when a user visits a maliciously designed webpage, causing the browser to resolve references incorrectly and expose data that should remain private.
Affected Systems
Google Chrome on Android versions earlier than 151.0.7922.169 are affected. The flaw does not apply to other platforms or later Chrome releases.
Risk and Exploitability
The vulnerability is listed as High severity by Chromium. No EPSS score is available and the issue is not in the CISA KEV catalog. Exploitation requires a user to load a malicious page, so it is user‑interaction dependent. While the attack vector is likely low in prevalence, the impact on an infected device is significant because sensitive user data can be read by the attacker.
OpenCVE Enrichment