Impact
A use-after-free flaw in the Skia graphics library, which Chrome’s Android browser uses to render web content, permits a remote attacker to trigger arbitrary code execution inside a sandboxed Chrome process through a specially crafted HTML page. The vulnerability, identified as CWE-416, occurs during the rendering of the page and allows the attacker to run code with the privileges granted to the sandboxed process.
Affected Systems
All Google Chrome for Android releases earlier than version 150.0.7871.47 are vulnerable, regardless of the underlying Android OS version. Any device that can load untrusted web content through Chrome—including browser tabs, email clients, or embedded web views—faces risk.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, yet the EPSS score of less than 1% suggests that exploitation in the wild is currently unlikely. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker must deliver crafted web content that the victim renders in Chrome, implying a likely attack vector of malicious HTML. The flaw allows code execution within the Chrome sandbox, but no break-out or privilege escalation beyond the sandbox is stated in the available information.
OpenCVE Enrichment
Debian DLA
Debian DSA