Impact
An input validation flaw in the Text component of Google Chrome for Android allowed a remote attacker who had already compromised the renderer process to supply a crafted HTML page that could escape the sandbox. The flaw is a classic CWE-20 problem where untrusted input is not properly sanitized, leading to potential sandbox escape and arbitrary code execution with elevated privileges on the device. The result is a remote sandbox escape that can compromise the entire system if the renderer has been taken over.
Affected Systems
All installations of Google Chrome for Android before version 150.0.7871.47 are affected, including devices shipped with older Chrome releases or those that have not yet received the latest updates.
Risk and Exploitability
The vulnerability has a CVSS base score of 9.6, indicating high severity, yet an EPSS score of less than 1% and absence from CISA’s KEV catalog suggest it is unlikely to be exploited in the wild. Exploitation requires the attacker to first compromise the renderer process—a significant prerequisite that lowers the likelihood. Nevertheless, if the prerequisites are met, the impact is severe, allowing privilege escalation and broad device compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA