Impact
A buffer overflow occurs in the Dawn rendering engine of Google Chrome on Android devices before version 151.0.7922.169. By delivering a specially crafted HTML page, a remote attacker can cause the overflow, which allows execution of arbitrary code outside of the browser sandbox. This can compromise the confidentiality, integrity, and availability of the affected device.
Affected Systems
The vulnerability affects Google Chrome on Android running any build earlier than 151.0.7922.169. All Android devices that ship with Chrome versions prior to that release are impacted.
Risk and Exploitability
The flaw is scored as 9.6 on CVSS with an EPSS of < 1 %, indicating a high severity but a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The description states that a remote attacker can trigger the overflow via a crafted HTML page delivered over the network, implying that malicious or compromised websites may be the primary attack vector. Once the Chrome update is installed, the risk is effectively eliminated.
OpenCVE Enrichment
Debian DLA
Debian DSA