Impact
The vulnerability in Google Chrome on Android allows an attacker with social engineering capabilities to manipulate the user interface and bypass system access restrictions, effectively elevating privileges. This is achieved through incorrect authorization handling that does not verify the source of UI interactions. The compromised user may experience unauthorized actions triggered by the attacker, such as executing privileged commands or accessing sensitive data.
Affected Systems
Google Chrome running on Android devices with versions earlier than 152.0.7977.65 is impacted. No other vendors or product variations are listed.
Risk and Exploitability
Chromium classifies the issue as low severity with a CVSS score of 4.3, and an EPSS score of <1% is available, indicating a low exploitation probability. The lack of a CISA KEV listing further suggests that the vulnerability is not actively exploited in the wild. The attack requires a social engineering component, meaning it relies on user interaction; therefore, the risk is mitigated only when users remain vigilant, but any user who falls for the social engineering vector could be compromised.
OpenCVE Enrichment
Debian DLA
Debian DSA