Impact
Information can leak from the Sharing feature in Google Chrome on Android up to version 152.0.7977.65. A user can be tricked into installing an additional app that gains local access, allowing that app to read sensitive data from the browser. The weakness is an information‑leak flaw described by CWE-200 and the Chromium security team rates the vulnerability as low severity.
Affected Systems
The vulnerability affects Google Chrome for Android versions before 152.0.7977.65. Only devices running the affected releases of Chrome on Android are in scope. Upgrading to the fixed release removes the flaw.
Risk and Exploitability
The risk of exploitation is limited to local attackers who can convince a user to install a co‑installed app. Because the EPSS score is < 1% and the vulnerability has a CVSS score of 5.1, there is currently low evidence of active exploitation. The flaw is developer‑controlled and requires social engineering, so the exploitability is moderate but constrained by the need for user interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA