Impact
A use‑after‑free flaw in the Autofill component of Google Chrome allows a remote attacker who has already compromised the renderer process to trigger memory corruption. The vulnerability can be exploited by delivering a specially crafted HTML page that manipulates freed memory, potentially enabling the attacker to escape the browser sandbox and execute arbitrary code on the device.
Affected Systems
Google Chrome on Android, version 149.0.7827.53 and earlier.
Risk and Exploitability
The flaw has a CVSS score of 8.3, indicating high severity. No public EPSS value is available, and the issue is not listed in the CISA KEV catalog. Successful exploitation would require the attacker to compromise the renderer process—typically via a malicious web page—and construct the attack payload to reach the freed memory area. Once the attack succeeds, sandbox escape could allow full control of the Chrome process and potentially the underlying operating system.
OpenCVE Enrichment