Impact
An inappropriate implementation in the WebView component of Google Chrome on Android allows a remote attacker who has already compromised the renderer process to construct a specially crafted HTML page that can potentially escape the browser sandbox, thereby gaining elevated privileges. This flaw could enable the attacker to execute arbitrary code outside the confined environment of the renderer, impacting the confidentiality, integrity, and availability of the underlying Android system.
Affected Systems
Google Chrome on Android devices with versions older than 149.0.7827.53 are affected. These releases include the buggy WebView implementation that permits a malicious HTML page to attempt a sandbox escape.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.6, indicating critical severity. The EPSS score is below 1%, signifying a low predicted exploitation probability, and the issue is not listed in the CISA KEV catalog. The likely attack vector requires a remote attacker to first compromise the renderer process; once that is achieved, a crafted HTML page can trigger a sandbox escape. Given the high severity but low exploitation likelihood, the risk remains elevated and warrants prompt remediation.
OpenCVE Enrichment
Debian DSA