Impact
A race condition in the GPU driver within Google Chrome on Android, present before version 149.0.7827.53, can allow a remote attacker who has already compromised the renderer process to execute code outside the sandbox. The flaw resides in improper deallocation of GPU resources, classified as CWE‑416. The potential impact includes full system compromise, data exfiltration, and persistence on the affected device.
Affected Systems
Android devices running Google Chrome prior to version 149.0.7827.53 are affected. No specific version list beyond the stated upper bound is provided, so any installation earlier than the referenced build is vulnerable.
Risk and Exploitability
The CVE carries a medium severity rating according to Chromium’s security assessment. Exploitation requires a remote attacker to first gain control of the renderer process, which typically means the attacker must compromise local user privileges or deliver malicious content. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation at present. However, the attack path is plausible for threat actors who can deliver crafted HTML to a user, making timely patching prudent.
OpenCVE Enrichment