Impact
A crafted HTML page can trigger Google Chrome on Android (versions prior to 153.0.8010.36) to expose stored password data to a remote attacker. The vulnerability involves an information leak (CWE-200) where the browser fails to isolate or protect credentials from malicious content. The compromised data includes usernames and passwords that may allow credential‑based attacks against user accounts, but the flaw does not affect the integrity or availability of the browser or the device.
Affected Systems
Google Chrome for Android versions older than 153.0.8010.36. The issue is limited to the Android platform and does not affect other operating systems or browsers.
Risk and Exploitability
Chromium assigns a low severity to this issue, indicating that an attacker must deliver a malicious HTML page and rely on the user visiting that page. No privileges or additional credentials are required. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, exposure of credentials is a serious concern for users of affected versions.
OpenCVE Enrichment
Debian DLA
Debian DSA