Impact
A buffer overflow occurs in the Dawn rendering engine of Google Chrome on Android. The flaw enables a remote attacker to create a crafted HTML page that triggers the overflow, allowing the execution of arbitrary code outside the browser sandbox. This constitutes a remote code execution vulnerability that can compromise confidentiality, integrity, and availability of the device.
Affected Systems
The issue affects Google Chrome for Android versions below 151.0.7922.169. The vulnerability is present in the stable channel on all Android platforms that ship the affected Chrome build.
Risk and Exploitability
The flaw carries a critical severity rating by Chromium authorities. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through a malicious or compromised website that serves the crafted HTML content. Remediation requires applying the updated Chrome release that mitigates the overflow; once patched, the risk is nullified.
OpenCVE Enrichment