Impact
An incorrect reference resolution bug in the WebView component of Google Chrome for Android lets a remote attacker craft an HTML page that may override normal web origin policy checks. This flaw could enable the malicious page to access or manipulate data that should be isolated from other origins, compromising the integrity or confidentiality of user data. The Chromium security team evaluated the threat as low severity, indicating that while the impact is significant, it does not necessarily allow arbitrary code execution or full system compromise.
Affected Systems
Google Chrome running on Android devices with a version earlier than 152.0.7977.65 is affected. The vulnerability exists in all Chrome builds that include the WebView feature for that release line. Devices with later updates reference the patched code and are not vulnerable.
Risk and Exploitability
The exploit probability is low due to an EPSS score of less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. A remote attacker would likely need to host a malicious web page that is loaded inside Chrome’s WebView, thereby leveraging the reference resolution bug to subvert the origin policy. Because the CVSS score is 4.3, the risk remains primarily around data leakage from otherwise siloed web origins.
OpenCVE Enrichment
Debian DLA
Debian DSA