Impact
The vulnerability is a missing authorization check in the WebAppInstalls component of Google Chrome on Android. An attacker who has already compromised the renderer process can serve a specially crafted HTML page that causes the application to reveal sensitive information to the attacker. The impact is the disclosure of confidential data handled by the browser.
Affected Systems
Google Chrome browsers on Android devices with a version earlier than 152.0.7977.65 are affected. The fact that the CVE description refers only to Chrome on Android implies that other platforms are not affected; this inference is drawn from the lack of mention of those platforms in the official statement.
Risk and Exploitability
Chromium lists the issue with a CVSS score of 5.3 (Medium severity). An exploit requires the attacker to gain control of the renderer process, which normally demands bypassing the browser sandbox or leveraging another vulnerability. EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of successful exploitation remains uncertain. If an attacker can compromise a renderer, the information leakage can occur via a malicious HTML page.
OpenCVE Enrichment
Debian DLA
Debian DSA