Impact
Incorrect authorization in the WebAppInstalls component of Chrome on Android, before version 152.0.7977.65, allows a remote attacker to use a crafted HTML page to bypass system access restrictions. This flaw can enable the attacker to perform actions that would normally be prevented by the operating system's permission model, potentially exposing sensitive data or compromising device functionality. The vulnerability is not a direct code execution flaw but escalates privileges that can be used for malicious purposes.
Affected Systems
Google Chrome for Android versions older than 152.0.7977.65 are affected. The issue is present in all builds that include the vulnerable WebAppInstalls module before the security patch. Devices running these versions are at risk when they load malicious, crafted web pages from the internet.
Risk and Exploitability
The Chromium severity rating for this issue is Medium, and the CVSS score of 4.3 reflects that assessment. No known exploit or usage pattern has been reported in public threat intelligence. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that wide‑scale exploitation has not been observed. Nevertheless, the attack path requires delivery of a crafted HTML page to the device, so any user who visits a malicious site or is tricked into opening a link could be affected. Organizations should treat this as a vulnerability that requires timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA