Impact
A buffer overflow occurs in the ANGLE graphics stack within Google Chrome for Android. A crafted HTML page can trigger this overflow, allowing a remote attacker to execute arbitrary code outside the browser sandbox. The vulnerability is a classic heap overflow (CWE‑122) and is rated high severity by Chromium’s own assessment.
Affected Systems
The flaw affects Android builds of Google Chrome prior to version 152.0.7977.65. Users running older builds, whether installed from the Play Store or from manufacturer firmware, remain vulnerable.
Risk and Exploitability
The vulnerability can be triggered simply by opening a malicious HTML page, meaning any site that hosts such content could be an attack vector. The CVSS score of 8.8 indicates high severity, while an EPSS score of < 1 % signals that exploitation is unlikely yet the potential impact is severe. The vulnerability is not listed as a known exploited vulnerability in CISA’s KEV catalog, but administrators should still treat it as a high‑priority risk.
OpenCVE Enrichment
Debian DLA
Debian DSA