Impact
Insufficient validation of untrusted input in Google Chrome on Android prior to build 148.0.7778.96 allows a local attacker to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. This flaw corresponds to CWE‑20, Input Validation. Based on the description, it is inferred that the attacker could execute malicious JavaScript or embed harmful HTML within the browser, potentially exfiltrating user data or performing unauthorized actions as the user.
Affected Systems
Devices running Google Chrome on Android with a build number earlier than 148.0.7778.96 are affected. The vulnerability applies to any device where a malicious or compromised extension can be installed or where an existing benign extension can deliver untrusted data.
Risk and Exploitability
The vulnerability has a CVSS score of 4.4, indicating a moderate severity rating, and no EPSS score is available. The CVE is not listed in the CISA KEV catalog. Attack requires local device access to install or modify a Chrome Extension, so the likelihood of exploitation is moderate. The potential impact on confidentiality, integrity, and availability is confined to the browser context, but can be significant if malicious scripts are executed. Prompt patching is recommended to mitigate possible exploitation.
OpenCVE Enrichment
Debian DSA