important · Mobile — Chrome
An exploited V8 write gives crafted pages native execution inside Chrome for Android's renderer.
Affects
Chrome for Android, Google’s mobile web browser running on Android devices.
The victim must load attacker-controlled HTML, which triggers the V8 out-of-bounds write and reaches code execution inside the renderer sandbox.
Detail and 3 sources
Chrome for Android 153.0.8010.36 contains the corresponding fix.
Chain to watch
Load crafted HTML in Chrome for Android→↓Trigger the V8 out-of-bounds write→↓Execute code inside the renderer sandbox→↓No Android-applicable sandbox escape has been established.
Unverified chainIdentify the observed exploitation chain and determine whether it contained an Android sandbox escape.
The major Android containment boundary still holds in the established chain; we do not know whether observed exploitation included an Android-applicable escape.