Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 147.0.7727.117 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| chrome | cert_advisory | 90% | |
| android | cve_cpe | 95% | |
| linux | linux_kernel | cve_cpe | 95% |
| microsoft | windows | cve_cpe | 95% |
Updated vendor to Microsoft and added that the exploit is now available in Microsoft Edge.
Updated severity to CRITICAL, added affected version 147.0.7727.101, and noted that no exploit is available.
Initial creation