Impact
A use‑after‑free bug in Chrome’s WebView on Android enables a local attacker to run arbitrary code by supplying a malicious file. The flaw, classified as CWE‑416 and CWE‑825, can compromise the device’s confidentiality and integrity. The vulnerability is considered medium severity by Chromium’s internal scoring system.
Affected Systems
Google Chrome for Android versions earlier than 149.0.7827.53 are affected. The issue is specific to the WebView component that renders content from locally stored files.
Risk and Exploitability
The exploit requires a local attacker who can place a crafted file on the device – for example via a malformed download or malicious app. With a CVSS score of 7.8, the vulnerability is considered high severity, but the EPSS score indicates a low probability (<1%) and the vulnerability is not listed in CISA’s KEV catalog. The risk remains moderate but should be mitigated promptly by updating Chrome.
OpenCVE Enrichment
Debian DSA