Impact
A use‑after‑free flaw in the Autofill module of Google Chrome for Android allows a remote attacker who can supply a specifically crafted HTML page to potentially escape the browser sandbox. The vulnerability, classified as CWE‑416, arises when memory is freed and then reused, enabling corrupted program state outside the intended sandbox boundaries.
Affected Systems
All Android installations of Google Chrome prior to version 150.0.7871.115 are affected. The vulnerability resides in the Autofill component and applies to all Chrome for Android builds before that revision.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity, while the EPSS score of < 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. A likely attack vector would involve delivering the malicious HTML content to the device, for example through a compromised or malicious web page accessed via a phone’s browser. If the conditions are met, an attacker could achieve unauthorized code execution outside the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA