Impact
A race condition in the WebAppInstalls component of Google Chrome on Android allows a remote attacker, who can rely on social engineering, to bypass the web origin policy. When successfully exploited, the attacker can cause Chrome to treat a malicious co‑installed application as a trusted web origin, potentially exposing user data or enabling further attacks within the browser context.
Affected Systems
The vulnerability exists in Google Chrome for Android versions prior to 152.0.7977.65. All Android devices running any unsupported Chrome build are at risk. Chrome versions 152.0.7977.65 and later have the fix applied.
Risk and Exploitability
The flaw is a race condition (CWE-362) that can be exploited remotely through a malicious Android application that is co‑installed with Chrome. Because the attack relies on social engineering to install the co-app, the primary attack vector is user interaction. The CVSS score is 4.3 and the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The Chromium advisory rates the severity as high, indicating a significant risk if the flaw is leveraged.
OpenCVE Enrichment
Debian DLA
Debian DSA