Impact
An input validation flaw in ANGLE within Google Chrome allows an attacker controlling the renderer process to pass crafted input that bypasses the renderer sandbox, enabling code execution beyond the renderer’s restricted environment and potentially compromising the user’s system.
Affected Systems
Google Chrome versions prior to 150.0.7871.47. The flaw exists and affects the renderer process that handles web content.
Risk and Exploitability
The Chromium security team classified the issue as critical, with a CVSS score of 9.6; the EPSS score is less than 1% and it is not listed in CISA’s KEV catalog. Exploitation requires the attacker to already control or influence the renderer process, inferred from the description; the likely attack vector involves malicious web content or a compromised extension. Successful sandbox escape would grant code execution outside the renderer, enabling further system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA