Impact
An integer overflow in the WebGL implementation of Google Chrome for Android permits a remote attacker to craft an HTML page that can trigger undefined behavior, enabling execution of arbitrary code outside Chrome’s sandbox. This flaw jeopardizes confidentiality, integrity, and availability by potentially allowing an attacker to run code with the privileges of the browser process, thereby compromising the entire host device.
Affected Systems
The vulnerability affects Google Chrome versions for Android prior to 155.0.8059.39. Devices running any earlier Android build that includes this Chrome release are susceptible. Exact patch notes are referenced in the official Chrome release blog.
Risk and Exploitability
Chromium rates the flaw as High severity and lists it as an integer overflow (CWE-190). The CVSS score is 9.6, indicating critical risk. The EPSS score is unavailable, and the vulnerability is not present in the CISA KEV catalog, suggesting no widespread active exploitation yet. However, the attack requires a crafted HTML page, most likely delivered over the network, and hinges on the browser’s WebGL code path. Because the flaw can lead to arbitrary code execution beyond the sandbox, the risk remains high until a vendor patch is applied. Users should consider the attack vector to be web-based and perform continuous monitoring of Chrome updates.
OpenCVE Enrichment