Impact
Missing authorization in Chrome CustomTabs on Android devices that run a version earlier than 152.0.7977.65 can let a local attacker gain control beyond the sandbox of the Chrome application. The flaw allows a co‑installed app that is able to open CustomTabs to run arbitrary code on the device, potentially affecting all data and system components. This is identified as a CWE‑862 vulnerability, indicating a failure to enforce proper authorization checks.
Affected Systems
The affected product is Google Chrome for Android; the vulnerability exists only in releases prior to 152.0.7977.65. Any device that has Chrome installed from a channel older than this build and that receives CustomTabs requests from other locally installed applications is at risk.
Risk and Exploitability
The vulnerability does not appear in the CISA KEV catalog and the EPSS score is < 1%, indicating a very low but non‑zero likelihood of exploitation. The Chromium classification as medium severity combined with a CVSS score of 7.4 suggests a moderate risk level. The attack vector requires the attacker to be in physical or local administrative control of an Android device and to have a co‑installed application capable of opening CustomTabs. If exploited, the flaw would allow bypassing the Chrome sandbox boundaries, enabling execution of code at a privilege level equal to or greater than Chrome, potentially affecting all data and system components.
OpenCVE Enrichment
Debian DLA
Debian DSA