Impact
A use‑after‑free flaw exists in the WebView component of Google Chrome on Android. A crafted HTML page can trigger an invalid memory reference, allowing a local attacker to execute arbitrary code inside Chrome’s sandbox process. The vulnerability is classified as high severity by Chromium security and is identified as CWE‑416, a consequential memory misuse that can lead to arbitrary code execution.
Affected Systems
The flaw affects Google Chrome on Android running versions prior to 149.0.7827.197. No specific branch or release outside of Android is known to be impacted. Users of the latest desktop Chrome releases are not affected by this particular bug.
Risk and Exploitability
Because the vulnerability requires a local attacker with access to render a malicious HTML page, the attack vector is local. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploits at this time. However, the high CVSS score for the Chromium security severity suggests that if an attacker gains the local execution capability, they could escape the sandbox and compromise the host system. The patch is available only in newer Chrome releases for Android.
OpenCVE Enrichment