Impact
Chrome’s ANGLE component performed insufficient validation of untrusted input, enabling a compromised renderer process to use a crafted HTML page to break out of its sandbox and potentially execute code on the host. The flaw is a classic input validation weakness, identified as CWE‑20.
Affected Systems
All users running Google Chrome version 150.0.7871.46 or earlier are affected; only Chrome’s renderer process uses ANGLE in these releases.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, yet the EPSS score of <1% shows a very low likelihood of exploitation. Because the attacker must first compromise the renderer process, the attack surface is more limited than generic remote code execution, and the vulnerability is currently not listed in CISA’s KEV catalog, indicating no widespread exploitation at this time.
OpenCVE Enrichment
Debian DLA
Debian DSA