Impact
For Google Chrome on Android, a use‑after‑free flaw in the WebGL implementation allows a remote attacker to potentially escape the browser sandbox by loading a specially crafted HTML page. An exploit could grant the attacker elevated privileges on the device, effectively enabling code execution or unauthorized data access. The vulnerability is listed with Critical severity by Chromium and maps to the use‑after‑free weakness identified by CWEs 416 and 825.
Affected Systems
The affected product is Google Chrome for Android. Versions prior to 151.0.7922.109 are vulnerable. Users running these builds are susceptible to the described sandbox escape.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, yet the CVSS severity is Critical. Attackers can trigger the flaw by serving a malicious web page that exercises the WebGL path, potentially without any user interaction beyond visiting the page. Because this is a use‑after‑free bug in a widely used browser component, the risk of exploitation is high, especially for users who install content from untrusted sources.
OpenCVE Enrichment
Debian DLA
Debian DSA