Impact
A remote attacker can craft a malicious HTML page that exploits insufficient validation of untrusted input in Chrome's ANGLE component to attempt a sandbox escape. This vulnerability falls under input validation weaknesses (CWE‑20, CWE‑807) and, if successfully exploited, could allow code to run outside the browser sandbox, compromising system integrity. The Chromium project has rated it as Medium severity, indicating a significant but not catastrophic risk if mitigated.
Affected Systems
The flaw affects Google Chrome browsers that shipped before the 149.0.7827.53 update; no specific minor versions are listed. Any Chrome installation lacking the patch could be vulnerable.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector requires the attacker to host a crafted HTML page that a victim visits, potentially triggering the sandbox escape. The high CVSS score of 9.6 indicates a severe risk, and although there is no evidence of widespread exploitation, the potential to escape the browser sandbox and compromise system integrity makes this a top priority for remediation.
OpenCVE Enrichment
Debian DSA