Impact
The vulnerability is a use‑after‑free flaw in the Resources component of Chrome for Android. When a renderer process is compromised, an attacker can trigger the bug through a crafted HTML page and potentially escape the renderer sandbox. This could allow malicious code to run with higher privileges than the renderer is permitted. The weakness is classified as CWE‑416 and CWE‑825, a classic use‑after‑free and memory corruption issue.
Affected Systems
Google Chrome on Android versions prior to 151.0.7922.109 are affected. Devices running these releases are exposed to the risk if a user visits a malicious web page or a compromised renderer process exists.
Risk and Exploitability
The flaw has a CVSS score of 8.3, indicating high severity. The EPSS score is <1%, presenting a low probability of exploitation. The attack requires a compromised renderer, but a skilled attacker could trigger the use‑after‑free by serving a malicious HTML page that exploits the bug. Because the vulnerability allows a sandbox escape, the impact could range from local data exfiltration to code execution beyond the renderer’s permissions. The flaw is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA