Impact
A use‑after‑free flaw in the Audio component of Google Chrome on Android allows an attacker who has compromised the renderer process to execute arbitrary code outside the sandbox through a crafted HTML page. The flaw is rated as Medium severity by Chromium security, yet the CVSS score of 8.3 reflects a high level of risk.
Affected Systems
Google Chrome on Android devices running a version prior to 152.0.7977.65 are affected. The vulnerability applies to the stable channel of Chrome on Android and any custom builds that include the same audio code path.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity, while the EPSS score is <1% and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to compromise the renderer process first, and then serve a malicious HTML page that triggers the use‑after‑free in the Audio subsystem, enabling code execution outside the sandbox with renderer privileges. If successful, this could lead to full device compromise or execution of privileged code.
OpenCVE Enrichment
Debian DLA
Debian DSA