Impact
A use‑after‑free flaw in the Dawn rendering engine of Google Chrome for Android allows a remote attacker to write to memory that has already been freed. The vulnerability can be triggered by a crafted HTML page loaded in the browser. If successfully exploited, the attacker may execute arbitrary code outside the Chrome sandbox, potentially compromising the device’s operating system. The weakness is identified as CWE-416.
Affected Systems
Google Chrome for Android versions prior to 153.0.8010.52. The affected builds use the Dawn graphics backend. Users of older stable channel releases before September 2026 are at risk.
Risk and Exploitability
The CVSS score is 9.6, indicating critical severity. The EPSS score is less than 1%, suggesting a low probability of exploitation at the time of analysis, and the vulnerability is not yet listed in CISA’s KEV catalog. Nonetheless, the flaw can be triggered remotely via a malicious web page, so untrusted browsers or webpages should be treated as potentially dangerous until a patch is applied. The primary attack vector is through web content rendered by Chrome on Android devices.
OpenCVE Enrichment
Debian DLA
Debian DSA