Impact
A race condition in the Start process of Google Chrome on Android allows a local attacker to execute arbitrary code outside the sandbox using a co-installed application. The flaw is classified as CWE-367 and may enable code execution with limited privileges on the device.
Affected Systems
Google Chrome on Android devices with versions prior to 152.0.7977.65 are vulnerable. The issue is triggered by a co-installed app; any supported Android platform running the affected Chrome build can be impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating a high level of severity. The EPSS score is reported as less than 1% and the flaw is not listed in CISA KEV. Exploitation requires local access and social engineering to get the attacker to install a malicious co-app, so the attack vector is local. Once triggered, the attacker can run code outside the browser sandbox with the device user's privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA