Impact
An out-of-bounds write in the WebGL component of Google Chrome on Android allows a malicious attacker to inject code that runs outside the sandbox, effectively granting arbitrary code execution power through a specially crafted HTML page. The vulnerability is classified as Critical by Chromium's security team, indicating highest severity. The weakness is a classic buffer overrun (CWE-787).
Affected Systems
Google Chrome for Android devices running any version prior to 153.0.8010.36 is affected. The flaw specifically impacts the WebGL implementation within the browser engine; older or newer releases that have fixed the bug are not impacted.
Risk and Exploitability
The CVSS score of 9.6 confirms the vulnerability's critical severity. The EPSS score is <1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, via a crafted HTML page served over the web. Because the exploit requires the crafted HTML page to be opened in Chrome, a user interaction is necessary. Once triggered, the attacker can escape the browser sandbox and execute arbitrary code on the device with the privileges of the user’s account.
OpenCVE Enrichment
Debian DLA
Debian DSA