Impact
The vulnerability arises from insufficient validation of untrusted input in Chrome’s WebShare component on Android. An attacker who has already compromised the renderer process could serve a crafted HTML page that exploits this weakness, enabling a sandbox escape. This privilege elevation allows the attacker to execute code outside the browser’s limited sandbox, potentially compromising the device and accessing sensitive data.
Affected Systems
Google Chrome for Android versions prior to 148.0.7778.216 are impacted. Any device running an older build of Chrome is susceptible if the attacker can target the renderer process.
Risk and Exploitability
The failure is rated high in Chromium’s severity, with a CVSS score of 9.0 and an EPSS score of <1%. Because the exploit requires a compromised renderer and a crafted page, the attack vector is an attacker‑controlled web page delivered via WebShare. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet, but the potential for remote code execution warrants immediate attention.
OpenCVE Enrichment