Impact
The vulnerability is a missing authorization check in Android Google Chrome that permits a local-installed attacker to read data that should be protected by Chrome's sandbox, leading to potential leakage of user credentials or other private data. The weakness is identified as CWE-862.
Affected Systems
Android users running Google Chrome versions earlier than 153.0.8010.47 are affected. The issue applies to the stable channel build and impacts devices on the Android platform where Chrome is preinstalled or installed by users.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity vulnerability, and the EPSS score of less than 1% suggests a model requiring local access and a malicious or compromised co-installed app to succeed, so remote exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog, which further reduces the perceived risk.
OpenCVE Enrichment