Impact
Incorrect authorization in Chrome’s certificate handling on Android before 153.0.8010.36 permits a remote attacker to spoof the browser’s address bar using crafted network traffic. This flaw allows forged addresses to appear as if they belong to legitimate sites.
Affected Systems
Google Chrome for Android versions earlier than 153.0.8010.36 are affected. Users running these builds should update to a newer release to mitigate the spoofing risk.
Risk and Exploitability
The vulnerability is identified by CWE‑863 and has a CVSS score of 4.8, indicating a low risk level. The EPSS score is <1%, suggesting a very low exploitation probability, and it is not listed in the CISA KEV catalog, indicating limited known exploitation. An attacker with network access can inject crafted packets or modify responses to trigger the incorrect authorization, allowing the spoofed address bar to appear. The low exploitation effort and lack of privileged prerequisites suggest that the risk is primarily to users who may be deceived while browsing on affected Chrome installations.
OpenCVE Enrichment
Debian DLA
Debian DSA