Impact
Server‑side request forgery in Chrome Mobile allows a remote attacker to use a crafted HTML page to bypass system access restrictions, potentially enabling unauthorized access to internal resources. This weakness can be exploited through social engineering, using a malicious page that triggers requests to internal services.
Affected Systems
Google Chrome Mobile for all devices running a version earlier than 153.0.8010.36 is affected. No other products or versions are listed as vulnerable. The product name "Chrome Mobile" is inferred from the description rather than explicitly stated.
Risk and Exploitability
With a CVSS score of 9.8, this vulnerability is considered critical. Although the EPSS score of less than 1% indicates a very low probability of exploitation so far, the high severity rating suggests that if successful, the attack would enable unauthorized access to internal resources through a crafted HTML page. The attack still requires a user to open a malicious page, so it remains a social‑engineering vector rather than an automated remote exploit.
OpenCVE Enrichment
Debian DLA
Debian DSA