Impact
The vulnerability is a type‑confusion bug in ANGLE, a graphics platform used by Chrome, that can lead to heap corruption when a specially crafted HTML page is rendered. Classified as CWE‑787, this defect jeopardizes the integrity of the browser’s memory. The CVE description indicates that the flaw can be exploited remotely by an attacker who serves a malicious page.
Affected Systems
The affected versions are all builds of Google Chrome that precede 149.0.7827.53 on any stable channel. The issue relates exclusively to the Chrome browser and does not affect other Google products or the underlying operating system. Upgrading to version 149.0.7827.53 or newer removes the vulnerability.
Risk and Exploitability
An attacker only needs to host a malicious web page to trigger the flaw, meaning ordinary web browsing can be used as the attack vector. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog; the CVSS score of 8.8 and Chromium’s Critical severity label indicate a high potential impact. Given that no privileged input is required, the risk of exploitation remains significant.
OpenCVE Enrichment