Impact
A use‑after‑free bug in the GPU driver code of Google Chrome on Android allows a malicious HTML document to exploit a freed memory area after a renderer process crash. The defect can lead to a sandbox escape, granting an attacker arbitrary code execution on the device. The weakness is a classic memory‑corruption error, identified as CWE‑416.
Affected Systems
Google Chrome for Android versions earlier than 150.0.7871.182 are vulnerable. Any device running a compromised renderer process that loads a specially crafted web page may be affected.
Risk and Exploitability
The CVSS score of 9.6 marks the issue as critical, yet the EPSS score of <1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. Attackers would need to entice an Android device to load malicious content that triggers the renderer crash and then use the freed memory to escape the sandbox. No public exploits are known, but the high severity warrants immediate attention.
OpenCVE Enrichment
Debian DLA
Debian DSA