Impact
This vulnerability is a server‑side request forgery in the Omnibox of Google Chrome on Android. An attacker can control the browser to send unauthorized requests to internal or external resources, which can bypass normal system access restrictions. The weakness is identified as CWE‑918. The effect is limited to network traffic manipulation; while it can expose internal services or lead to data exposure, it does not directly provide remote code execution.
Affected Systems
Google Chrome running on Android devices with a version earlier than 153.0.8010.52. No other vendors or product versions are mentioned as affected.
Risk and Exploitability
The CVSS score of 3.7 indicates a medium severity risk. The EPSS score of less than 1% suggests that exploitation is unlikely to be widespread. The vulnerability is not listed in CISA KEV. The attack typically requires social engineering, with a user entering a malicious URL in the Omnibox that triggers the forged request. No additional system privileges or pre‑exploitation conditions are noted.
OpenCVE Enrichment
Debian DLA
Debian DSA