Impact
A use‑after‑free bug in the Dawn rendering engine of Google Chrome on Android, affecting builds prior to 153.0.8010.36, lets a remote attacker execute arbitrary code outside the browser sandbox by loading a specially crafted HTML page. This flaw is classified as CWE‑416 and provides the attacker with full control over the victim device once the vulnerable page is rendered, compromising confidentiality, integrity, and availability.
Affected Systems
Google Chrome on Android devices running a browser version earlier than 153.0.8010.36. Users on the stable channel should be on the 153.0.8010.36 build or later to receive the fix.
Risk and Exploitability
The vulnerability can be exploited from a remote web page, so an attacker only needs to host the malicious content on a site that the user visits. While the EPSS score of 0.00297 (≈0.3%) indicates a low probability of exploitation and the flaw is not yet listed in the CISA KEV catalog, the Chromium security severity is High and the widespread use of Chrome on Android give attackers a realistic pathway to compromise devices. The CVSS score of 9.6 indicates critical severity. Given the remote nature of the attack and the outside‑sandbox execution, the risk is significant for any Android device using an affected Chrome build.
OpenCVE Enrichment
Debian DLA
Debian DSA