Impact
The vulnerability is a clickjacking flaw in TrustedWebActivities on Google Chrome for Android. A local attacker can use a co‑installed app to display a fake address bar, tricking users into believing they are viewing a legitimate webpage. The attacker could then perform phishing or other malicious actions while the user thinks they are interacting with Chrome. This weakness is classified as CWE‑1021.
Affected Systems
Google Chrome on Android devices running versions earlier than 153.0.8010.36 are affected. The issue specifically targets TrustedWebActivities that allow apps to replace or overlay Chrome’s UI elements.
Risk and Exploitability
The CVSS score of 4.0 indicates a medium severity impact. The EPSS score is less than 1 percent, suggesting a low likelihood of exploitation, and this vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a local co‑installed application that overlays the Chrome UI and can spoof the address bar. It is inferred the attacker would need permissions to draw over other apps. The vulnerability could lead to user deception or credential theft, but no widespread exploitation has been reported. The overall impact is considered moderate.
OpenCVE Enrichment
Debian DLA
Debian DSA