Impact
A use‑after‑free bug in the Web MIDI implementation of Chrome on Android allows a malicious HTML page to trigger heap corruption, giving an attacker the ability to execute arbitrary code with the privileges of the browser process. This vulnerability is catalogued as CWE‑416 and CWE‑825 and can compromise the integrity and confidentiality of the device.
Affected Systems
The flaw affects Google Chrome browsers running on Android devices with versions older than 146.0.7680.178. The vendor’s March 2026 release notes list this issue in the stable channel, meaning any Android device that has not yet upgraded Chrome to 146.0.7680.178 or newer remains vulnerable.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity condition, while the EPSS score of less than 1% reflects a low current exploitation probability. The attack requires a victim to load a crafted web page, making it a web‑based exploit path. No publicly known exploits are documented, and the vulnerability is not yet in the CISA KEV catalog, but it still poses a significant remote code execution risk if left unpatched.
OpenCVE Enrichment
Debian DSA