Impact
The vulnerability is a use‑after‑free in the Permissions component of Google Chrome on Android prior to 147.0.7727.101. A remote attacker can execute arbitrary code if a user is compelled to perform specific UI gestures while a crafted HTML page is displayed. This flaw is classified under CWE‑416 and compromises the integrity and confidentiality of the device by allowing code execution within the browser process.
Affected Systems
Google Chrome for Android versions earlier than 147.0.7727.101 are affected. The April 2026 stable channel update (147.0.7727.101) contains the patch that mitigates this issue.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, though the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a malicious web page that relies on user interaction to trigger the use‑after‑free. Once triggered, an attacker gains the same privileges as the browser, enabling arbitrary code execution on the device. The overall risk is significant due to the remote nature of the attack and the potential for widespread exploitation through crafted sites.
OpenCVE Enrichment