Impact
The vulnerability is a use‑after‑free flaw in the printing subsystem of Google Chrome for Android. A remote attacker who can compromise a renderer process could craft a malicious HTML page that triggers a sandbox escape, potentially allowing execution of code outside the browser sandbox.
Affected Systems
Google Chrome on Android versions prior to 149.0.7827.103 are affected. Users running any earlier stable channel build of Chrome on Android devices are at risk until an update is applied.
Risk and Exploitability
Because the flaw requires a compromised renderer process and the delivery of a crafted HTML payload, the attack vector is likely Remote Delivery over the internet. The CVSS score is 8.3, the EPSS score is in the interval (0%,1%), and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been widely exploited in the wild. Nonetheless, the potential for sandbox escape warrants immediate attention, especially in environments where Chrome is used extensively.
OpenCVE Enrichment
Debian DSA