Impact
An observable discrepancy in CustomTabs on Google Chrome for Android, present in versions prior to 152.0.7977.65, allows a local attacker to obtain data from different origins through a co‑installed application. This flaw is classified as CWE‑203, indicating that information is improperly exposed to an attacker. The vulnerability can result in a confidentiality breach for data accessed through CustomTabs, with no denial of service or privilege escalation described.
Affected Systems
Google Chrome on Android, all versions before 152.0.7977.65. The affected systems include devices running any pre‑65 build of the Chrome stable channel on Android, with version numbers such as 152.0.0–151.x. No specific sub‑versions are listed beyond the upper bound.
Risk and Exploitability
Chromium rates this bug as medium severity, with a CVSS score of 2.9. The vulnerability requires a local malicious application that co‑installs with Chrome, allowing the attacker to access cross‑origin data. The attack vector is local and no remote exploitation pathway is described in the CVE data. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA