Impact
Chrome for Android versions earlier than 152.0.7977.65 contains a use‑after‑free bug in the Sessions module. The flaw can be triggered by a social‑engineering attack that forces the victim to perform a specific UI interaction. When triggered, the use‑after‑free allows the attacker to execute arbitrary code outside the browser sandbox. This results in full remote compromise of the device and is mapped to the memory corruption weakness CWE‑416.
Affected Systems
All users running Google Chrome on Android before version 152.0.7977.65 are affected. The vulnerability specifically targets the Sessions component in the mobile browser.
Risk and Exploitability
The CVE has a CVSS score of 9.6, indicating a high severity vulnerability. The EPSS score is < 1%, showing a very low probability of public exploitation. It is not listed in the CISA KEV catalog. Exploitation requires social engineering and user interaction, which limits the attack surface to end users. While the likelihood of widespread attacks is low due to the requirement for a crafted UI interaction, a successful exploitation would have a high impact, enabling code execution outside the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA