Impact
Insufficient validation of untrusted input in the GPU component of Google Chrome on Android allows a remote attacker who has already compromised the renderer process to craft a malicious HTML page that can potentially escape the browser sandbox and execute code outside the renderer. This input validation vulnerability (CWE‑20) could lead to full device compromise, giving the attacker read, modify, and execute arbitrary code.
Affected Systems
All Google Chrome for Android releases before 148.0.7778.216 are affected. Devices running these versions are vulnerable until the browser is updated to the patched build.
Risk and Exploitability
With a CVSS score of 9.0, the vulnerability is considered high severity by Chromium, but no EPSS score is published and it is not in the CISA KEV catalog. The likely attack vector requires a prior compromise of the renderer process, limiting the ease of exploitation from a purely remote attacker. However, if an attacker can reach the renderer, the flaw can be leveraged to escape the sandbox, potentially allowing full remote code execution.
OpenCVE Enrichment