Impact
Improper input validation in Google Chrome on Android prior to 152.0.7977.65 allows an attacker who has already compromised the renderer process to craft a malicious HTML page that can escape the sandbox and execute arbitrary code. This vulnerability is a CWE‑20 flaw and can give the attacker full device control, leading to data theft, malware installation, or further exploitation.
Affected Systems
Android versions of Google Chrome older than 152.0.7977.65 are affected. Users running any earlier Chrome release on Android devices face this risk and should upgrade to the latest stable channel.
Risk and Exploitability
The CVSS score of 8.3 signals high severity. EPSS score is <1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in CISA's KEV catalog, indicating no known widespread exploitation. Nevertheless, once a renderer‑process compromise is achieved—such as via a malicious web page—the sandbox escape can be leveraged to execute code outside the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA