Impact
An out-of-bounds read in the WebGL subsystem of Google Chrome on Android—affecting all releases prior to 148.0.7778.216—enables a remote attacker to potentially escape the browser sandbox by delivering a crafted HTML page. The flaw is a boundary violation (CWE‑125) and, if successfully exploited, could give the attacker unrestricted code‑execution rights on the device.
Affected Systems
Google Chrome on Android devices, any revision before the 148.0.7778.216 release. Users of the Chrome stable channel who have not yet updated are vulnerable.
Risk and Exploitability
Chromium labels the issue as Critical, but it is not listed in CISA’s KEV catalog and an EPSS score is not available. Exploitation requires a malicious webpage to be opened by a user, so the threat level depends on user exposure to such content. Successful exploitation could lead to remote code execution once the sandbox boundary is breached.
OpenCVE Enrichment