Impact
Google Chrome for Android contains a flaw in the CustomTabs component’s reference resolution logic that can be triggered by a crafted HTML page. The bug enables a remote attacker to cause the system to resolve references outside the intended scope, effectively bypassing built‑in access restrictions. This can let an attacker gain unauthorized access to other apps or system resources that should remain protected, potentially allowing the compromise of sensitive data or execution of privileged commands. The weakness is classified as a Reference Validation flaw, CWE-706.
Affected Systems
The vulnerability affects Chrome for Android versions earlier than 152.0.7977.65. Users running any unsupported older build are at risk until an updated release is installed.
Risk and Exploitability
The CVE has no public exploit score and is not listed in the CISA KEV catalog; the EPSS score is < 1%, indicating a very low probability of exploitation. Chromium security teams rate the issue as Low severity with a CVSS score of 4.3. The attack requires delivering a crafted HTML page that is opened in a CustomTabs session, which most likely implies user interaction or a malicious app distributing such content. Given the low severity and lack of a public exploit, the likelihood of exploitation is currently considered low, but the effect is high enough to warrant monitoring of affected devices.
OpenCVE Enrichment
Debian DLA
Debian DSA