Impact
The vulnerability is an out‑of‑bounds read and write in ANGLE, the graphics layer used by Chrome. This flaw can potentially lead to a sandbox escape, allowing an attacker who supplies a specially crafted HTML page to run non‑sandboxed code. The weakness is a classic out‑of‑bounds memory access that compromises integrity and confidentiality within the browser process. The official Chromium severity is listed as Critical, indicating that successful exploitation could grant full system privileges to the attacker.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. The issue applies to all platforms where ANGLE is enabled, which includes the stable desktop channel of Chrome. No other browsers or products are known to be impacted.
Risk and Exploitability
The vulnerability is remotely exploitable through a web page, implying that an attacker only needs to lure a victim to a malicious site. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the CVSS score of 9.6 indicates Critical severity, suggesting a high likelihood of exploitation in the wild. The lack of an official patch notice in the input implies that users of the affected Chrome version remain at risk until they upgrade. The attack requires the victim to load the crafted page, meaning a phishing or social‑engineering vector is a typical prerequisite.
OpenCVE Enrichment