Impact
Chrome on Android systems prior to version 153.0.8010.36 contains a missing authorization flaw in the craft network traffic and bypass operating‑system access restrictions. The vulnerability is classified as CWE‑862 and can potentially expose protected resources or enable further malicious activity if exploited.
Affected Systems
Android devices that run Google Chrome or include a Chrome‑based WebView component prior to version 153.0.8010.36 are affected. This includes all applications that embed the WebView in any mode before the update and applies to all users whose devices have not yet installed the patched release.
Risk and Exploitability
Based on the description, it is inferred that a remote attacker can exploit the missing authorization by sending crafted HTTP/HTTPS traffic to the vulnerable WebView. The EPSS score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates medium severity, and the potential for privilege escalation means that attackers may target unpatched systems, although widespread exploitation has not been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA