Impact
A flaw in the authorization logic for WebAPKs in Google Chrome for Android allows a local attacker to read data from WebAPKs belonging to another origin. The vulnerability is identified as an improper privilege management weakness (CWE‑863). An attacker who can co‑install a malicious app can leverage this flaw to obtain confidential information from a co‑installed WebAPK that normally would be protected by origin boundaries. The impact is primarily the compromise of information confidentiality and could be used to exfiltrate sensitive data exposed by the affected WebAPK.
Affected Systems
The vulnerability affects Google Chrome on Android installations running any version earlier than 154.0.8037.57. Systems with Chrome earlier than this patch level are vulnerable unless an alternative security measure is applied.
Risk and Exploitability
The CVSS score of 2.9 indicates a medium severity assessment. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is local and requires installation of a malicious co‑app, the likelihood of exploitation is moderate and depends on user behavior and device policies. Organizations that allow installation of apps from unknown sources or that configure WebAPKs with sensitive data should treat this as a medium‑risk issue and consider immediate patching or additional controls.
OpenCVE Enrichment
Debian DSA