Impact
The vulnerability is an incorrect authorization check in the CustomTabs component of Google Chrome on Android, allowing a local attacker to bypass the browser’s web origin policy via a co‑installed application. This flaw is identified as a missing authorization for an existing resource (CWE‑863). The result is that a malicious package installed alongside Chrome can access content that should be restricted by the browser’s origin boundaries, potentially exposing confidential data or enabling further compromise of the device.
Affected Systems
Google Chrome for Android versions older than 152.0.7977.65 are affected. Users of these builds on any Android device run the risk of exploitation by a local application bundled with or placed in the same user space as Chrome.
Risk and Exploitability
The flaw requires local execution of a co‑installed app, so the attacker must already have a package installed on the device. The EPSS score of 0.00168 indicates a very low but non‑zero probability of exploitation; the vulnerability is not listed in the CISA KEV catalog, and the CVSS score of 4.3 indicates moderate severity. Nonetheless, because it breaches web origin separation, it poses a significant confidentiality risk. An update that adds the missing authorization check mitigates the issue.
OpenCVE Enrichment
Debian DLA
Debian DSA