Impact
The flaw is a use‑after‑free in the ANGLE graphics library used by Google Chrome on Android. A malicious web page can trigger the defect, causing Chrome to run attacker supplied code outside the normal sandbox. The vulnerability is a critical issue that can lead to arbitrary code execution with the privileges of the Chrome process.
Affected Systems
Google Chrome for Android versions before 152.0.7977.65 are vulnerable. No additional product versions are listed, and the update to 152.0.7977.65 includes the fix.
Risk and Exploitability
Because the attack requires only a crafted HTML page, an attacker can deliver payloads via a malicious site or phishing email. The CVSS score is 9.6, indicating a critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits yet. Nevertheless, the exploitation path is clear: a user visiting the malicious page while Chrome is unpatched leads to remote code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA