Impact
The vulnerability is a use‑after‑free flaw in Chromium’s Bluetooth handling code that may allow an attacker who has already compromised the renderer process to escape the sandbox by delivering a specially crafted HTML page.
Affected Systems
Google Chrome for Android versions before 151.0.7922.72, including older Chrome releases that have not applied the latest stable update.
Risk and Exploitability
The CVSS score of 5.0 indicates medium severity while the EPSS score of less than 1% suggests low likelihood of spontaneous exploitation; the vulnerability is not listed in KEV. Exploitation requires an attacker to supply malicious HTML and first gain code execution in the renderer, making it a non‑trivial attack that could still lead to local privilege escalation if the conditions are met.
OpenCVE Enrichment
Debian DLA
Debian DSA