Impact
An out‑of‑bounds read bug affects the Tint component in Google Chrome for Android. A maliciously crafted HTML page can trigger the fault, allowing an attacker to read memory located inside the sandboxed renderer process and potentially expose sensitive data. The flaw is classified as CWE‑125, an off‑by‑one error that results in an information‑disclosure vulnerability.
Affected Systems
All Chrome Stable builds for Android older than version 152.0.7977.65 are affected. Devices running those releases should be considered at risk until they apply the patched update.
Risk and Exploitability
The vulnerability requires only a single malicious web page to be loaded in Chrome; no local privilege escalation or code execution is needed. The CVSS score of 6.5 reveals a medium severity, yet with an EPSS score of < 1% and no listing in CISA’s KEV catalog, the likelihood of exploitation presently appears low. However, the data leakage it enables could compromise user privacy. Chromium rates the issue as low severity.
OpenCVE Enrichment
Debian DLA
Debian DSA