Impact
Use‑after‑free vulnerability in the Skia graphics engine of Google Chrome on Android allows a malicious actor who gains control of the renderer process to escape the sandbox by serving a specially crafted HTML page. The flaw can be leveraged by a remote attacker to execute code outside the browser sandbox, compromising the device’s confidentiality, integrity, and availability. The weakness is a classic use‑after‑free, identified as CWE‑416, and is rated as critical by Chromium’s security team.
Affected Systems
Google Chrome for Android versions prior to 151.0.7922.109 are affected. Users running these releases on Android devices are at risk if a renderer process is compromised by a malicious web page.
Risk and Exploitability
The CVSS score is 8.3, and the EPSS score is unavailable, so the quantified risk cannot be expressed with precision. The flaw is listed as critical by Chromium and is not yet in the CISA KEV catalog. Exploitation requires the attacker to compromise the renderer process, which can be achieved by delivering malicious content through an HTML page. Once the renderer is compromised, the attacker may escape the process sandbox and gain broader system access. The lack of telemetry data means the real‑world exploit probability is uncertain, but the severity warrants immediate attention.
OpenCVE Enrichment
Debian DLA
Debian DSA