Impact
Type confusion in the ANGLE graphics library within Google Chrome allows a remote attacker to potentially escape the browser sandbox by delivering a specifically crafted HTML page. This flaw can lead to elevated privileges and unauthorized access to system resources, posing a notable risk to confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Google Chrome browsers prior to version 149.0.7827.53. No detailed version list is provided, so all installations of Chrome before the security release are considered at risk.
Risk and Exploitability
The CVSS score is 9.6, indicating a critical severity. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector appears to be remote; an adversary must supply a crafted HTML page that the victim views, which could be delivered via a malicious website or email. No exploit has been publicly reported, but the combination of type confusion and sandbox escape logic provides a plausible path for higher-privilege execution if the browser processes the malicious content.
OpenCVE Enrichment
Debian DSA