Impact
Race condition in Chrome permissions handling on Android devices allows an attacker to craft a web page that bypasses the browser’s web origin policy when the user opens it. This flaw can lead to unauthorized cross‑origin access to a web page’s resources or manipulation of page content, effectively exposing confidential data or enabling further attacks.
Affected Systems
Google Chrome for Android, including all versions released before 152.0.7977.65.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity. The EPSS score of less than 1% suggests that exploitation is expected to be rare. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been observed. An attacker would need to use social engineering to convince a user to open a specifically crafted HTML page. Given the low EPSS, the overall risk of real‑world exploitation is considered low.
OpenCVE Enrichment
Debian DLA
Debian DSA