Impact
The vulnerability arises from an improper release of a web resource in earlier versions of Google Chrome for Android. A remote attacker can use social engineering to deliver a crafted HTML page that exploits this flaw, enabling the attacker to bypass the browser’s web origin policy. The likely impact is that the attacker could read or manipulate data from other origins that should be isolated, potentially leading to data exposure or unauthorized actions.
Affected Systems
Google Chrome for Android mobile devices before version 152.0.7977.82 are affected. All builds on the stable channel that have not yet applied the update are at risk. No specific device model was mentioned, so any Android device running this Chrome version is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of < 1% suggests a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been documented. The flaw requires an end‑user to view a crafted HTML page, so social engineering is needed. Based on these metrics, the practical risk is moderate, but remediation should be prioritized to prevent potential cross‑origin data access.
OpenCVE Enrichment
Debian DLA
Debian DSA