Impact
The vulnerability is a missing authorization check in Chrome's Trusted Web Activities (TWA) implementation on Android devices. It allows a local attacker who can co‑install a malicious app to access TWA content and retrieve sensitive information that would normally be protected. This flaw is an information disclosure weakness identified as CWE-862.
Affected Systems
The issue affects Google Chrome for Android versions prior to 153.0.8010.36. Any device running an impacted Chrome build and that installs an app able to register a Trusted Web Activity is vulnerable.
Risk and Exploitability
Exploitation requires local privilege; an attacker must have the ability to install or modify an application on the target device. The vulnerability carries a Chromium security severity of high, with a CVSS score of 5.5 and an EPSS score of < 1%, and it is not listed in CISA's KEV catalog, indicating that widespread exploitation has not yet been observed. Nonetheless, devices with outdated Chrome and the presence of untrusted apps represent a significant risk for sensitive data exposure.
OpenCVE Enrichment
Debian DLA
Debian DSA