Impact
The vulnerability is a use‑after‑free flaw in the Input component of Google Chrome for Android. A remote attacker can deliver a specially crafted HTML page that triggers the flaw, causing the browser to execute arbitrary code within its sandboxed environment. The impact is that the attacker can run code with the privileges of the sandbox, potentially extracting data or enabling further exploits if sandbox escape mechanisms are bypassed.
Affected Systems
Google Chrome on Android versions earlier than 149.0.7827.53. All devices running those builds are susceptible until upgraded to the fixed 149.0.7827.53 release or newer.
Risk and Exploitability
The flaw is triggered remotely via a crafted HTML page, so an attacker only needs to lure a user to a malicious site. No EPSS data is available, but the Chromium project rates it as high severity. The patch does not appear in the CISA KEV catalog, indicating no known exploitation at large scale yet. Nevertheless, the combination of remote trigger, high severity, and absence of mitigation suggests a significant risk to users who do not keep Chrome updated.
OpenCVE Enrichment