Impact
A missing authorization check in the Payments component of Google Chrome for Android versions older than 152.0.7977.65 could allow a remote attacker to bypass system access restrictions. By injecting a specially crafted HTML page and using social engineering, the attacker may manipulate the browser into executing payment-related actions that should normally be protected. This flaw corresponds to a missing authorization weakness (CWE-862) and could compromise the integrity of payment data or result in unauthorized transactions.
Affected Systems
Google Chrome running on Android devices with a version prior to 152.0.7977.65 is affected. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The vulnerability is classified as medium severity (CVSS 4.3), with an EPSS score of `< 1%` and it is not listed in the CISA KEV catalog. The likely attack vector is a manipulated HTML page that an unsuspecting user opens, triggering the payment flow without proper authorization checks. Because the flaw requires user interaction and social engineering, exploitation probability is moderate but not negligible and may vary by user awareness.
OpenCVE Enrichment
Debian DLA
Debian DSA