Impact
The vulnerability is a use‑after‑free bug in the Search functionality of Google Chrome for Android. A crafted HTML page can trigger the fault, allowing the attacker to execute arbitrary code outside the browser sandbox. This can lead to compromise of the device, extraction or modification of sensitive data, or further lateral movement within the mobile environment.
Affected Systems
Affected systems include Android devices running any version of Chrome before 152.0.7977.65. The issue is confined to the stable channel of the browser; later releases contain the fix.
Risk and Exploitability
Risk and exploitability are high, with a CVSS score of 9.6 indicating critical severity. No public exploits have been documented and the EPSS score is currently unavailable, but the vulnerability requires social engineering to gain a user’s attention to a malicious HTML page. Because the flaw permits code execution, the potential impact is high if successfully leveraged.
OpenCVE Enrichment
Debian DLA
Debian DSA