Impact
Insufficient validation of untrusted input in the WebView component of Google Chrome for Android before version 151.0.7922.72 could allow a malicious HTML page to trigger a sandbox escape, enabling code execution outside the isolated WebView environment. The vulnerability is related to improper input validation and insufficient use of security functionality, corresponding to CWE‑20 and CWE‑1286.
Affected Systems
Google Chrome for Android versions earlier than 151.0.7922.72. Any Android application that embeds an older WebView instance may also be exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates medium severity, and the EPSS score of less than 1 % suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote, requiring a crafted web page that the affected WebView will load; successful exploitation would result in code execution outside the sandboxed process.
OpenCVE Enrichment
Debian DLA
Debian DSA