Impact
A use‑after‑free condition in the ANGLE graphics library inside Google Chrome on Android allows a remote attacker who has already compromised the renderer process to mount a sandbox escape through a specially crafted HTML page. The flaw is classified as CWE‑416 (Use After Free) and CWE‑825 (Prior Data Exposure).
Affected Systems
The vulnerability affects the Google Chrome web browser on Android devices running any version prior to 151.0.7922.72. Devices that have not applied the July 2026 stable channel update remain susceptible.
Risk and Exploitability
The CVSS score of 5.8 indicates a medium severity, and the EPSS score of less than 1 % reflects a very low probability of exploitation in the wild. The vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires the attacker’s ability to influence the renderer process, which can be achieved by delivering malicious content from a compromised or malicious web page. Once the use‑after‑free is triggered, the sandbox escape can allow the attacker to execute code with higher privileges than the renderer process typically possesses.
OpenCVE Enrichment
Debian DLA
Debian DSA