Impact
The vulnerability is a use‑after‑free flaw in the GPU component of Google Chrome on Android prior version 150.0.7871.125. It can allow a remote attacker who has already compromised the renderer process to escape the browser sandbox and execute code outside of the browser’s safety boundaries; this is inferred from the stated use‑after‑free and sandbox escape keywords. The weakness is identified as CWE‑416.
Affected Systems
Google Chrome on Android versions older than 150.0.7871.125 is affected; earlier builds remain vulnerable until an upgrade is performed.
Risk and Exploitability
The flaw carries a CVSS score of 8.3, indicating high severity, and its EPSS score is less than 1 % while it is not listed in CISA KEV, suggesting that exploitation is currently unlikely. The attack requires an attacker to first gain control of the renderer process and then serve a crafted HTML page to trigger the use‑after‑free, after which sandbox escape can occur. This attack path is inferred from the described conditions and is considered complex.
OpenCVE Enrichment
Debian DLA
Debian DSA