Impact
A local attacker can use a co‑installed app to read cross‑origin data from Google Chrome on Android by exploiting an observable discrepancy in CustomTabs. This flaw permits the attacker to extract data that should be isolated to another origin, effectively leaking sensitive information. The weakness is governed by CWE‑203, which describes improper restriction of information disclosure.
Affected Systems
Google Chrome for Android versions before 152.0.7977.65 are affected. The issue arises in the CustomTabs functionality used by local applications to embed web content within Chrome.
Risk and Exploitability
The vulnerability requires local access to the device and a malicious co‑installed application; it does not allow remote code execution or privilege escalation. The CVSS score of 2.9 indicates a Low severity, while the EPSS score is less than 1%, showing a very low probability of exploitation. The vector is local, so an attacker must already have the ability to install or run apps on the device, but once that condition is met, sensitive data can be obtained unobtrusively.
OpenCVE Enrichment
Debian DLA
Debian DSA