Impact
A use‑after‑free error in the Messages component of Google Chrome on Android can be exploited by a remote attacker through a specially crafted HTML page. The flaw allows the attacker to potentially escape the browser sandbox, thereby gaining elevated privileges or executing code outside the browser environment. This vulnerability represents a classic memory corruption issue classified as CWE‑416 and a potential input handling flaw classified as CWE‑825.
Affected Systems
The affected product is Google Chrome for Android. Versions prior to 149.0.7827.53 are vulnerable. The issue is specific to the Messages interface within the browser, so it applies to all Android devices running the affected Chrome release.
Risk and Exploitability
The CVSS score of 9.6 signifies critical severity, indicating a high potential impact should an exploitation succeed. The EPSS score of < 1% suggests that exploitation attempts are presently unlikely, though not impossible. The vulnerability is not listed in the CISA KEV catalog. An attacker could remotely deliver a malicious HTML page via a web site or link, triggering the use‑after‑free flaw and potentially escaping the Chrome sandbox on Android. The lack of public exploits and the low EPSS score means exploitation is uncertain, but the critical CVSS and remote nature warrant proactive mitigation.
OpenCVE Enrichment
Debian DSA