Impact
An unbounded use‑after‑free occurs in the fullscreen rendering path of Google Chrome on Android. The bug is triggered when a web page aggressively requests to enter fullscreen; during the deallocation of internal resources the browser later reads memory that has already been freed. An attacker can construct a special HTML page that triggers this sequence, allowing them to execute arbitrary code within the context of the Chrome process. This flaw is identified as CWE‑416 and was rated as critical by the Chromium security team. Based on the description, it is inferred that the attacker’s only requirement is to serve a malicious HTML page that initiates a fullscreen transition.
Affected Systems
Google Chrome on Android versions earlier than 150.0.7871.47 are affected. Any user who opens a malicious web page that initiates a fullscreen request while using a vulnerable Chrome build is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating that if successfully exploited it would grant an attacker full control over the victim device. However, the EPSS score of <1% demonstrates that the likelihood of an active public exploit is very low at this time. Attacks would be carried out via a malicious web page that forces a fullscreen transition in the vulnerable Chrome build; no additional privileges or user interaction beyond opening the page are required. Based on the description, it is inferred that the attacker does not need elevated privileges or a separate exploit framework. Although the flaw is not currently listed in the CISA KEV catalog, its exploitation would remain highly destructive.
OpenCVE Enrichment
Debian DLA
Debian DSA