Impact
The vulnerability is a use‑after‑free in the core component of Google Chrome on Android, affecting versions prior to 149.0.7827.53. The flaw can be triggered by a crafted HTML page. If an attacker can compromise the renderer process, they may use the freed memory to execute arbitrary code, effectively escaping the browser's sandbox and potentially gaining full system access. This corresponds to CWE‑416, a use‑after‑free weakness, and CWE‑825, a data‑leak vulnerability.
Affected Systems
Google Chrome for Android versions earlier than 149.0.7827.53 are susceptible. The issue is confined to the Android edition; other platforms or later releases are not affected. Devices running these versions and which allow arbitrary HTML to be loaded in the renderer process are at risk.
Risk and Exploitability
The flaw carries a high severity rating according to Chromium. The CVSS score is 8.3, indicating high severity. The EPSS score is 0.00068, or less than 1%, suggesting a very low probability that the vulnerability will be exploited in the wild. The attack requires an attacker already able to run malicious code in the renderer process, typically by serving a crafted web page. A successful sandbox escape would give the attacker full control over the device, bypassing browser isolation. Because the vulnerability is not listed in CISA’s KEV catalog, there is no current evidence of widespread exploitation, but the high severity and the possibility of remote code execution warrant urgent patching.
OpenCVE Enrichment
Debian DSA