Impact
A use‑after‑free flaw in the Chrome UI on Android devices allows a remote attacker to trigger heap corruption by serving a specially crafted HTML page. The vulnerability can potentially enable arbitrary code execution, compromising confidentiality, integrity, and availability of the system. It originates from improper memory management when freeing browser objects, and is classified as CWE‑416.
Affected Systems
Google Chrome for Android versions prior to 149.0.7827.53 are affected. Users should verify that their device runs this or an earlier version of Chrome on the Android platform.
Risk and Exploitability
Chromium rates the severity of this issue as high. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because heap corruption can lead to arbitrary code execution, the risk is significant for any device that can render the crafted HTML. The likely attack vector is a malicious web page delivered over the network or locally via an app that injects HTML. Exploitation requires the attacker to make the target device load the crafted content, but once that condition is met, the consequences are severe.
OpenCVE Enrichment