Impact
A missing authorization check in Chrome's CustomTabs on Android allows a local attacker who has co‑installed an app with Chrome to access sensitive data that should be protected by Chrome's user context. This flaw is classified under CWE‑862 and can lead to the disclosure of confidential information. The vulnerability is not a remote exploit; it requires local or co‑installed application privileges, but it still compromises data integrity and confidentiality within the device. The security severity is medium as noted by Chromium.
Affected Systems
The affected vendor is Google; the product is Chrome for Android. Any device running Chrome versions prior to 152.0.7977.65 is vulnerable when CustomTabs is enabled and an attacker can install a companion app on the device.
Risk and Exploitability
The exploitation requires local installation of a malicious or compromised app, so the risk is limited to users who install such apps on a device with an outdated Chrome. The CVSS score is 5.1, the EPSS score is < 1%, and the vulnerability has not been listed in the CISA KEV catalog, indicating no known widespread exploitation at the time of analysis. However, because the flaw permits sensitive data leakage without proper authorization, administrators should prioritize updating Chrome to the latest stable release or disabling CustomTabs until a patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA