Impact
The vulnerability is an integer overflow in the WebView component of Google Chrome on Android, which allows a local attacker to cause a denial of service by loading a crafted malicious file. The flaw is categorized as CWE‑190 and CWE‑472, both representing integer overflow weaknesses. The impact is confined to the device where the attacker can execute the malicious file and cause the WebView to crash, resulting in application unavailability.
Affected Systems
Affected vendor: Google. Product: Chrome (Android). The flaw exists in versions prior to 149.0.7827.53, as the Advisory confirms that the issue was resolved in that release. No other product versions or sub‑products are listed.
Risk and Exploitability
The risk for an attacker is limited to local privilege. Since the prerequisite is that the attacker can place a malicious file on the device, the exploit likelihood depends on physical or local access. The EPSS score is 0.008% (<1%), indicating a very low exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting no evidence of widespread exploitation. The Chromium security severity is Low, indicating minimal impact beyond a local denial of service. The CVSS score of 5 indicates a medium level risk.
OpenCVE Enrichment
Debian DSA