Impact
This vulnerability arises from improper input validation in the GPU component of Google Chrome on Android, allowing a remote attacker who has already gained control of the renderer process to execute arbitrary code outside the sandbox. The flaw is identified as CWE-20 and can lead to full system compromise.
Affected Systems
Affected devices run Google Chrome on Android prior to version 152.0.7977.65. Any device with this build, including older Android releases, is susceptible unless updated.
Risk and Exploitability
The CVE is rated 8.3 on the CVSS scale, indicating high severity, and the EPSS score is below 1%, suggesting a low likelihood of immediate exploitation. It is not listed in the CISA KEV catalog. The flaw allows an attacker who has already compromised the renderer process to escape the sandbox and execute arbitrary code, exposing the entire device. Although no public exploits have been documented, the remote nature and high CVSS score warrant prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA