Описание
Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
A flaw was found in the WebView component of Google Chrome on Android. This vulnerability, known as a use-after-free, occurs when a program attempts to use memory after it has been freed, which can lead to unpredictable behavior. A local attacker could exploit this by tricking a user into opening a specially crafted HTML page. Successful exploitation could allow the attacker to execute arbitrary code within the confines of the application's security sandbox.
Отчет
This Important use-after-free flaw in the Chromium WebView component allows a local attacker to execute arbitrary code within the browser's sandbox. Exploitation requires user interaction, specifically enticing a victim to open a specially crafted HTML page. While local, the ability to execute code within the sandbox elevates the risk.
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebView in Google Chrome on Android prior to 149.0.7 ...
Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
EPSS
7.8 High
CVSS3