Impact
A use-after-free vulnerability in the Shared Tab Groups feature of Google Chrome on Android allows an attacker to run arbitrary code outside the browser sandbox by delivering a specially crafted HTML page. The flaw occurs when a freed memory pointer is reused, enabling the injected code to execute with the privileges of the browser process. This leads to remote code execution, giving an attacker full control over the compromised device.
Affected Systems
All Android installations of Google Chrome with a version prior to 152.0.7977.75 are affected. Devices running earlier releases of Chrome on Android must be examined for this vulnerability.
Risk and Exploitability
The EPSS score is not available, but the critical severity rating assigned by Chromium indicates a high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog yet, however it can be triggered through social engineering by convincing a user to open a maliciously crafted HTML page. Because the exploit occurs in the browser sandbox and allows code execution outside it, the impact is both wide and severe. Attackers do not need additional privileges beyond a user visiting the malicious page.
OpenCVE Enrichment