Impact
A race condition exists in the Transactions Platform of Google Chrome on Android before version 152.0.7977.65. The flaw can be triggered by a maliciously crafted HTML page, allowing a remote attacker, with social engineering, to bypass system access restrictions. The weakness is a classic race condition and is identified as CWE‑367.
Affected Systems
Google Chrome for Android users running any version prior to 152.0.7977.65 are affected. The issue does not apply to Chrome versions newer than the stated cutoff or to non‑Android variants.
Risk and Exploitability
Chromium labels the vulnerability with low severity, and the CVSS score is 5.3. The EPSS score indicates a probability of exploitation less than 1 percent, and the issue is not listed in the CISA KEV catalog. The attack requires a user to open a specifically crafted HTML page, so it relies on social engineering and user interaction. Given the low severity rating and limited exploitation probability, the overall risk is considered moderate but still actionable.
OpenCVE Enrichment
Debian DLA
Debian DSA