Impact
An improper implementation of the GPU subsystem in Google Chrome for Android allows a remote attacker to read data from the process memory using a specially crafted HTML page. The flaw permits extraction of potentially sensitive information, which could include personal data, credentials, or other confidential material stored in memory, exposing the victim to privacy violations or further attacks. This represents a direct information‑exposure weakness in the application.
Affected Systems
Google Chrome on Android versions prior to 148.0.7778.216 are affected. Users running any older build of Chrome on Android devices should verify their version and consider upgrading.
Risk and Exploitability
The vulnerability is rated High by Chromium security. EPSS score indicates a very low exploitation probability (0.00035 or < 1 %). It is not listed in CISA KEV. A remote attacker can exploit the flaw by delivering a crafted web page to the target, typically through compromised or malicious sites. The attack vector is therefore inferred to be remote via the browser. The severity of the potential data disclosure warrants immediate attention, especially in environments that process sensitive information.
OpenCVE Enrichment