Impact
The vulnerability is an information leak in the Intents handling mechanism of Google Chrome on Android. A remote attacker can craft an HTML page that, when opened in a vulnerable Chrome installation, causes the browser to expose sensitive data from the device. This flaw is a classic confidentiality bypass identified as CWE-200; the exploit allows reading data that should not be publicly available, potentially compromising user privacy.
Affected Systems
Google Chrome for Android versions older than 152.0.7977.65 are affected. Users running any Chrome build prior to this revision and expressing intent data may be at risk when visiting maliciously crafted web pages.
Risk and Exploitability
The issue has a CVSS score of 6.5, indicating medium severity, and an EPSS score indicating a very low but nonzero exploitation probability (<1%). It is not listed in the CISA KEV catalog. The attack requires the victim to open a crafted HTML page in a vulnerable Chrome on Android. No authentication or elevated privileges are needed, making the exploit practically available to remote attackers who can serve the malicious page.
OpenCVE Enrichment
Debian DLA
Debian DSA