Impact
The vulnerability is an out-of-bounds write in ANGLE, a graphics abstraction layer used by Chrome on Mac. The CVSS score of 9.6 indicates high severity. An attacker who is already able to compromise the renderer process can supply a specially crafted HTML page to trigger the overflow. The write can corrupt memory and enables the attacker to escape the renderer sandbox, potentially executing arbitrary code with a higher privilege level. This flaw is classified under CWE-787 and represents a significant security risk when the attacker gains the initial renderer foothold.
Affected Systems
Google Chrome running on macOS versions prior to 149.0.7827.53 is affected. Only the Mac desktop channel of Chrome is mentioned; other operating systems are not listed, so the impact is limited to Mac users with older Chrome builds.
Risk and Exploitability
The vulnerability has a high severity rating in Chromium's internal scoring, with a CVSS score of 9.6, but the EPSS score is <1%. The flaw is not listed in the CISA KEV catalog, suggesting that no widespread exploitation has been observed yet. However, because the attacker must first compromise the renderer process—a condition that is difficult but not impossible—the risk remains moderate. The lack of exploit probability data and the absence of a publicly confirmed exploit reduce immediate threat but do not remove the need for remediation.
OpenCVE Enrichment
Debian DSA