Impact
A use‑after‑free vulnerability exists in the GPU component of Google Chrome on Android. When triggered by a crafted HTML page, the flaw corrupts GPU memory buffers, allowing a remote attacker to escape Chrome’s sandbox and potentially execute code with the privileges of the browser process. The weakness is identified as CWE‑416 and is rated critical by Chromium’s internal assessment.
Affected Systems
Google Chrome for Android versions prior to 150.0.7871.128 are affected. The vulnerability exists in the GPU driver code and impacts all devices running those Chrome builds at the time of release.
Risk and Exploitability
The CVSS score of 9.6 indicates a very high severity. The EPSS score is listed as < 1 %, suggesting that current exploitation likelihood is low, and the vulnerability is not yet catalogued in CISA’s KEV list. The attack scenario requires an attacker to serve a specially crafted HTML page to a user, which, when rendered by Chrome, triggers the use‑after‑free in the GPU kernel. Once the sandbox is broken, the attacker could execute arbitrary code within the browser process. This attack vector is inferred from the vulnerability description, as it is not explicitly detailed in the data.
OpenCVE Enrichment
Debian DLA
Debian DSA