Impact
A race condition in the GPU driver of Google Chrome on Android, described as a use‑after‑free flaw, can allow a remote attacker who has already compromised the renderer process to escape Chrome’s sandbox by delivering a crafted HTML page. This vulnerability is classified as CWE‑368 and CWE‑416.
Affected Systems
The vulnerability applies to instances of Google Chrome running on Android devices that are prior to build 149.0.7827.53. No other version or platform is mentioned.
Risk and Exploitability
The CVSS score of 9.6 indicates a severe risk. Exploitation requires that the attacker has control over the renderer process and can supply a malicious HTML page that triggers the race condition to achieve a sandbox escape. The EPSS score of <1% indicates a low but non‑zero likelihood of successful exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been observed.
OpenCVE Enrichment
Debian DSA