Impact
The vulnerability is a use‑after‑free in the GPU component of Google Chrome for Android, which allows a remote attacker who has already compromised the renderer process to potentially escape the sandbox via a crafted HTML page. The flaw is a classic use‑after‑free, classified as CWE‑416. If successful, the attacker could execute arbitrary code with higher privileges than the browser, leading to a remote code execution that could compromise the device.
Affected Systems
Google Chrome for Android, versions prior to 149.0.7827.115, are affected. All Android users running these versions are at risk until they upgrade to a patched release.
Risk and Exploitability
Chromium rates the severity as high. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known public exploitation at this time. The flaw requires a remote attacker to deliver a crafted HTML page while having control over the renderer process, which could be achieved through an already compromised site or via drive‑by download. If exploited, the attacker could escape the renderer sandbox and compromise the host. Given the high severity and lack of public exploitation evidence, administrators should treat this as a high‑risk vulnerability pending patch.
OpenCVE Enrichment