Impact
Out of bounds memory access in the WebGL implementation of Google Chrome permitted a remote attacker to potentially escape the browser sandbox through a specially crafted HTML page. This critical vulnerability could allow the attacker to execute arbitrary code in the host operating system, thereby compromising confidentiality, integrity, and availability of the device.
Affected Systems
The vulnerability affects Google Chrome for Android versions prior to 146.0.7680.153. No other operating systems or Chrome versions are listed as affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact. The EPSS score is below 1%, suggesting a low probability of exploitation at this stage. The vulnerability does not appear in the CISA KEV catalog, implying no publicly known exploits yet. An attacker would need to deliver a malicious web page and convince a user to open it in the vulnerable Chrome browser on an Android device.
OpenCVE Enrichment
Debian DSA