Impact
A buffer overflow arises during GPU operations in Google Chrome for Android versions earlier than 153.0.8010.36. The integer overflow can be triggered by a specially crafted HTML page that a remote attacker can supply, potentially allowing execution of arbitrary code outside the browser sandbox. The flaw falls under CWE-190, reflecting an arithmetic overflow vulnerability. The threat is that a malicious webpage could exploit this defect to escape the browser process and gain full control of the device.
Affected Systems
The vulnerability affects Google Chrome on Android devices running any version before 153.0.8010.36. Any user who visits a malicious webpage in an affected version is at risk. There is currently no device‑specific restriction; all impacted Android installations using the affected Chrome build are vulnerable.
Risk and Exploitability
The issue has a CVSS score of 9.6, indicating a high severity. The exploit requires only a crafted HTML page accessed through a remote attacker, implying that the attack vector is a web‑based input. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, but the high CVSS score and its ability to escape the sandbox make exploitation potentially damaging. Users should expect that an attacker could compromise device security if the flaw is leveraged.
OpenCVE Enrichment
Debian DLA
Debian DSA