Impact
An inappropriate implementation in the Downloads component of Google Chrome for Android allows a remote attacker to bypass system access restrictions by serving a crafted HTML page Incorrect Enforcement of Access Control (CWE-841). The vulnerability requires a user to open the malicious page, so the attacker must rely on social engineering to deliver the exploit.
Affected Systems
Google Chrome for Android versions prior to 153.0.8010.36 are affected. Any Android device that has not been updated to this build or newer contains the flaw, including stable channel releases for all device types.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, reflecting Medium severity. The EPSS score is < 1% and it is not listed in the CISA KEV catalog. Exploitation requires user interaction: a malicious HTML page must be opened or bookmarked, which is typically achieved through a phishing link or suspicious message. While the risk is moderate due to the need for social engineering, the impact of the privilege escalation is significant, making timely patching essential.
OpenCVE Enrichment
Debian DLA
Debian DSA