Impact
A local information‑leak flaw exists in Chrome’s CustomTabs implementation on Android devices running versions prior to 152.0.7977.65. The flaw allows a co‑installed application that runs in the same device context to read data from another app’s WebView, exposing cross‑origin information such as personal data or session credentials. The impact is a breach of confidentiality for data stored within Chrome’s WebView component, although the flaw does not provide remote code execution or elevated privileges.
Affected Systems
The vulnerability affects Google Chrome on Android. Any device running Chrome prior to version 152.0.7977.65 is susceptible. The issue is limited to the Chrome application and does not extend to other applications unless they use the CustomTabs feature.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. Chromium assigns the flaw a Medium severity rating (CVSS 5.5). Exploitation requires a local attacker who can install a malicious app on the same device; no remote or network‑based vector is documented. The risk remains moderate because the attacker must have physical access or have compromised the device through another mechanism, but once in place, sensitive data can be harvested.
OpenCVE Enrichment
Debian DLA
Debian DSA