Impact
Incorrect authorization in WebView on Android allows a remote attacker who has already compromised the renderer process to execute arbitrary code outside the Chrome sandbox via a crafted HTML page. This flaw means that code running in the renderer can escape the browser’s security boundaries and potentially impact other applications or the operating system. The weakness is classified as CWE‑863, indicating a failure to enforce proper authorization checks on user input or context. Based on the description, the likely attack vector involves delivering a malicious HTML page to the WebView renderer.
Affected Systems
The affected product is Google Chrome for Android. Versions earlier than 153.0.8010.36 are impacted. All Android devices running a legacy Chrome build prior to that release, especially those that expose the WebView renderer to content from untrusted sources, are susceptible.
Risk and Exploitability
Because exploitation requires prior compromise of the renderer process, the attack surface is limited to scenarios where the attacker can inject malicious web content or achieve remote code execution within the renderer. Chromium rates the vulnerability as Medium. The EPSS score indicates less than 1%, and the issue is not listed in CISA KEV. Once the renderer is compromised, the attacker can gain code execution with higher privileges, posing a significant risk. The likely attack vector involves delivering crafted HTML content to the WebView renderer process.
OpenCVE Enrichment
Debian DLA
Debian DSA