Impact
A use‑after‑free bug exists in Chrome’s WebView component on Android versions before 146.0.7680.178. When an attacker has already compromised the renderer process, a specially crafted HTML page can trigger the flaw, potentially breaking out of the renderer’s sandbox and allowing execution of code with higher privileges. This flaw is mapped to CWE‑416, reflecting an error in memory management that can lead to severe security compromise.
Affected Systems
Google Chrome for Android is impacted for builds older than 146.0.7680.178. The issue requires the presence of a vulnerable Chrome installation and an elevated renderer process; other browsers or desktop Chrome editions are not listed as affected by the current information.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitability requires that an attacker first subvert the renderer process, then deliver a malicious HTML payload; successful exploitation could lead to sandbox escape and potential remote code execution with elevated privileges.
OpenCVE Enrichment
Debian DSA