Impact
The vulnerability is an improper input validation flaw in Google Chrome’s SafeBrowsing feature on Android devices. A crafted HTML page can trick a remote attacker into bypassing normal system access restrictions, potentially granting elevated privileges. The described defect is categorized under CWE‑20 and has a medium severity rating by Chromium security.
Affected Systems
Android installations of Google Chrome with versions earlier than 153.0.8010.36 are affected. Users on these releases are at risk if they visit malicious or social‑engineering webpages that exploit this flaw.
Risk and Exploitability
The exploit requires a remote attacker to supply a specially crafted HTML page to a target device, leveraging social engineering. The EPSS score is <1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 rates the vulnerability as moderate, showing that while the attack’s impact could be significant, it requires user interaction and is not trivially automated. If unpatched, attackers could use this path to elevate privileges or access protected resources.
OpenCVE Enrichment
Debian DLA
Debian DSA