Impact
A heap buffer overflow occurs in the GPU component of Google Chrome on Android, triggered by a crafted HTML page and enabling an out-of-bounds memory write. The flaw is a classic buffer‑overflow weakness (CWE‑120) and an out-of-bounds write weakness (CWE‑122) and the CVE description does not state that code execution is achieved; it only identifies the ability for a remote attacker to corrupt heap memory.
Affected Systems
The vulnerability affects Google Chrome for Android versions prior to 148.0.7778.168, including all earlier stable channel releases on Android devices.
Risk and Exploitability
Chromium rates the issue as high severity, but the CVSS score of 4.3 indicates moderate overall risk; EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote and requires the victim to load a malicious HTML page in Chrome; once rendered, the buffer overflow can corrupt memory. Given Chrome’s widespread use on Android, the potential impact spans a large user base, making timely remediation important.
OpenCVE Enrichment
Debian DSA