Impact
An integer overflow occurs in the GPU subsystem of Google Chrome for Android that can be triggered by loading a specially crafted HTML page. The flaw allows a remote attacker to perform an out‑of‑bounds memory access, and the Chromium security team has rated it as a medium severity issue.
Affected Systems
Google Chrome for Android versions earlier than 149.0.7827.53 are affected. All newer Chrome releases and other Google Chrome products are not impacted.
Risk and Exploitability
The vulnerability can be exposed remotely through a web page, meaning any device with an Internet browser running the vulnerable Chrome version is at risk. The EPSS score is <1% and the vulnerability is not listed in CISA KEV. With a CVSS score of 8.8, the vulnerability is rated high severity, and the potential for out‑of‑bounds memory access further increases risk. Attackers would likely need to entice the victim to visit or load the malicious page, and further exploitation would depend on additional conditions that are not described in the CVE data.
OpenCVE Enrichment
Debian DSA