Impact
The vulnerability is an out‑of‑bounds read and write in ANGLE, a graphics abstraction layer used by Chrome on Android. It allows a remote attacker, via a crafted HTML page, to potentially escape the browser sandbox, gaining unauthorized access to system resources and compromising data confidentiality and integrity. This flaw maps to buffer overflow weaknesses where memory bounds are not properly enforced, allowing manipulation of memory beyond intended limits.
Affected Systems
The flaw affects Google Chrome for Android versions earlier than 150.0..0.7871.182 build of Chrome is vulnerable.
Risk and Exploitability
The EPSS score of less than 1% suggests exploitation is currently rare, but the lack of a known KEV listing does not eliminate risk. The CVSS score of 9.6 reflects a critical severity, emphasizing the seriousness of this vulnerability. The attack vector is inferred to be remote, as a malicious access when rendered by the browser. Once the vulnerability is triggered, sandbox escape is possible, compromising the device. The vulnerability is rated high by Chromium. Continuous monitoring and timely patching are advised.
OpenCVE Enrichment
Debian DLA
Debian DSA