Impact
The vulnerability involves an externally controlled reference within Chrome's WebView on Android. If a malicious actor manages to compromise the renderer process, a specially crafted HTML page can cause the process to escape its sandbox boundaries and run arbitrary code. The weakness is identified as CWE-610, which represents unauthorized or illegitimate access to privileged resources. The impact of such an escape is a full compromise of the device's security context for the affected user or application, potentially allowing the attacker to read, modify, or execute data beyond its normal permissions.
Affected Systems
Affected tenants are users of Google Chrome on Android devices running versions prior to 152.0.7977.65. The vulnerability specifically targets the WebView component integrated into Chrome, which is employed to display web content within applications.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3, indicating high severity and is classified as a hover of risk given its requirement for a compromised renderer process. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker delivering a crafted HTML page to a user running an unpatched version of Chrome on Android. Once the renderer process is compromised, the attacker can execute code outside the sandbox, elevating privileges on the device. The lack of a publicly disclosed exploit and the high severity score suggest the risk is present but not imminent; however, any reachable renderer process would enable this attack.
OpenCVE Enrichment
Debian DLA
Debian DSA