Impact
Google Chrome for Android contains a use‑after‑free that can be triggered by a crafted HTML page to execute arbitrary code within the sandbox, giving the attacker control of code execution only inside the sandbox. The vulnerability is classified as CWE‑416: Use‑After‑Free.
Affected Systems
Android devices running Chrome versions earlier than 150.0.7871.47 are affected. The flaw resides in the WebView part of the Chrome application.
Risk and Exploitability
The vulnerability can be exploited remotely by providing a crafted HTML page that a user opens or that a WebView loads. The CVSS score of 8.8 indicates a high severity, while the EPSS score of < 1% suggests a very low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. No additional prerequisites beyond a crafted HTML page are required for exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA