Impact
A malformed WebGL buffer in Chrome for Android allows an attacker to write data beyond the bounds of a heap allocation. The resulting out‑of‑bounds write can corrupt memory used by the renderer process, enabling execution of arbitrary code outside the browser sandbox. This flaw is a classic example of a buffer overflow (CWE‑787) and directly compromises the confidentiality and integrity of the user’s device.
Affected Systems
The vulnerability appears in the Google Chrome browser on Android devices with versions older than 152.0.7977.82. Any device running a Chrome binary prior to that build is affected, regardless of geographic or hardware configuration. The flaw is limited to the WebGL context used by the browser; it does not affect native Android applications.
Risk and Exploitability
The flaw is rated as having high severity by Chromium security, and the attack vector requires a crafted HTML page that the victim must load in a vulnerable Chrome instance. Because it is a remotely exploitable memory corruption, an attacker could achieve full code execution on the device. A CVSS score of 9.6 indicates a critical risk. Exploit probability (EPSS) is not reported, and the vulnerability is not listed in CISA’s KEV catalog, but the severity and the nature of the exploit suggest a moderate likelihood of abuse in targeted attacks. The absence of an EPSS score does not diminish the need for timely patching.
OpenCVE Enrichment
Debian DLA
Debian DSA