Impact
An out‑of‑bounds write occurs in ANGLE, a graphics library used by Google Chrome, when processing a crafted HTML page on Android. This flaw permits an attacker to escape the browser sandbox, potentially allowing the execution of arbitrary native code on the device. The weakness is a classic out‑of‑bounds write, classified as CWE‑787, and the Chromium team rates its severity as Critical. The impact therefore spans confidentiality, integrity, and potentially availability if the attacker can modify or disable process resources.
Affected Systems
Google Chrome running on Android devices prior to version 151.0.7922.109 is affected. This includes any user who installed that stable channel build or an earlier one on an Android device. The vulnerability resides in the ANGLE component of Chrome’s rendering engine.
Risk and Exploitability
The flaw is a remote code execution vulnerability that can be triggered by a malicious web page rendered by Chrome on Android. Because it requires the victim to interact with a crafted page, the attack vector is remote with user interaction. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 9.6 demonstrates that it is considered critical, suggesting a high potential for exploitation if the flaw is in a frequently used component. Without an available exploit yet, the risk remains theoretical but significant for users on affected Chrome releases.
OpenCVE Enrichment
Debian DLA
Debian DSA