Impact
This vulnerability arises from a use‑after‑free bug in the WebGL implementation of Chrome on Android. A crafted HTML page can trigger a memory corruption that allows an attacker to execute arbitrary code with privileges that exceed the browser’s sandbox. The impact is remote code execution that can compromise the device, exfiltrate data, or enable further attacks.
Affected Systems
Google Chrome versions on Android lower than 152.0.7977.75 are vulnerable. The issue affects all Android devices running these Chrome versions, regardless of device manufacturer or OS build, until the security patch is applied.
Risk and Exploitability
The CVSS score is not publicly listed but the Chromium severity is marked critical, indicating a high‑consequence risk. EPSS data is unavailable and the vulnerability is not currently listed in the CISA KEV catalog, which does not imply low risk. The likely attack vector is a remote attacker delivering a malicious HTML page that the victim unknowingly opens. Successful exploitation requires the victim to view the page, and the code runs with elevated privileges outside the browser sandbox.
OpenCVE Enrichment