Impact
A buffer overflow exists in the WebGL implementation of Google Chrome on Android devices, allowing a remote attacker to execute arbitrary code outside the browser sandbox through a specially crafted HTML page. The flaw is a classic stack corruption that can lead to full system compromise, as it provides execution privileges beyond the confined browsing environment. The impact is therefore remote code execution, which threatens confidentiality, integrity, and availability of the affected device.
Affected Systems
Google Chrome running on Android devices with versions earlier than 153.0.8010.52 is affected. Users of the Chrome stable channel on Android older than this release are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 9.6, indicating critical severity. The EPSS score of less than 1% suggests that exploitation remains theoretical at present, and the vulnerability is not listed in the CISA KEV catalog. It can be leveraged remotely by hosting a malicious web page or by having the victim view a webpage from an untrusted source.
OpenCVE Enrichment
Debian DLA
Debian DSA