Impact
The vulnerability is an incorrect authorization check in Google Chrome for Android that allows a crafted HTML page to bypass system access restrictions, enabling an attacker to elevate privileges from a regular user to a higher level and undermine device security. This flaw is identified as CWE-863 (Authorization Bypass for Local Privilege Escalation).
Affected Systems
Devices running Google Chrome for Android earlier than version 153.0.8010.36 are affected. The issue applies to all Android models that ship with the affected Chrome package version, and no other platforms or browsers are mentioned.
Risk and Exploitability
The CVE has a CVSS score of 6.5, rating it as medium severity, and is not listed in the CISA KEV catalog. EPSS score is < 1%, indicating a very low but non-zero exploitation likelihood; the precise likelihood of exploitation remains unknown. The vulnerability can be triggered by a remote attacker who lures the victim to a malicious webpage. The exploitation requires the victim to load the crafted page in Chrome, making it a client‑side attack that could compromise device security if the user visits a malicious site.
OpenCVE Enrichment
Debian DLA
Debian DSA