Impact
An out-of-bounds read vulnerability in the WebView component of Google Chrome on Android allows a remote attacker, once the renderer process has been compromised, to read memory outside the sandbox. The attack payload is delivered via a crafted HTML page and can expose private data stored in memory. The Chromium team rated the severity as medium.
Affected Systems
Any device running Google Chrome for Android versions earlier than 153.0.8010.36 is affected. Updating to Chrome 153.0.8010.36 or later removes the vulnerability. The flaw resides in the WebView rendering engine used by Chrome on Android.
Risk and Exploitability
Although the EPSS score is low at 0.00225 (about 0.2 %), indicating a low but non‑zero likelihood of exploitation, the CVSS score remains 6.1, which is medium severity. The vulnerability requires a compromised renderer process and is delivered via a crafted HTML page, so exploitation is not trivial. Attackers can conduct the attack remotely by hosting malicious content that the browser renders, resulting in an out‑of‑bounds read that could expose sensitive data in memory. The risk to users is primarily the exposure of memory‑resident secrets rather than a full sandbox escape.
OpenCVE Enrichment
Debian DLA
Debian DSA