Impact
A missing authorization check in the WebView component of Google Chrome for Android allows a remote attacker to send crafted network traffic that the browser incorrectly treats as authorized. This flaw is classified as an authorization bypass (CWE‑862) and has a CVSS score of 6.5, which indicates medium severity according to the CVSS scale, but the CVE description notes a low Chromium security severity. The potential impact is that the attacker could gain trusted access and bypass device restrictions, although no direct code execution capability has been reported.
Affected Systems
Devices running any version of Google Chrome for Android older than 153.0.8010.36, regardless of build channel, are affected. The issue applies to all scenarios where the WebView component loads external content within the Chrome environment.
Risk and Exploitability
EPSS score is <1% and the CVSS score is 6.5; Chrome is not listed in the CISA KEV catalog, suggesting that exploitation has not been widely observed. The likely attack vector involves remote delivery of crafted network traffic, inferred from the description indicating that an attacker could leverage social engineering to persuade a user to load malicious content. If successful, the attacker could gain trusted access and bypass device restrictions, although no direct code execution capability is reported.
OpenCVE Enrichment
Debian DLA
Debian DSA