Impact
A use‑after‑free flaw located in the WebView component of Google Chrome for Android allows a remote attacker that delivers a carefully crafted HTML page to trigger a heap corruption. The CVE description indicates that the impact could affect confidentiality, integrity, and availability of the victim system, though the specific consequences are not explicitly stated. (Based on the description, it is inferred that such heap corruption could potentially lead to arbitrary code execution.)
Affected Systems
All Android devices running Google Chrome older than version 149.0.7827.53 are affected. The issue was present in the stable channel on Android and affects any application that embeds Chrome’s WebView component.
Risk and Exploitability
The EPSS score of <1% indicates a very low but non‑zero probability of exploitation, and the flaw is not listed in the CISA KEV catalog, indicating no known public exploits at this time. The CVSS score of 8.8 indicates high severity. The vulnerability allows remote delivery of a crafted HTML page that can trigger heap corruption in Chrome WebView. Based on the description, it is inferred that such heap corruption could compromise confidentiality, integrity, and availability of the victim system.
OpenCVE Enrichment
Debian DSA