Impact
An improper implementation of the ANGLE graphics engine in Google Chrome allows an attacker who serves a specially crafted HTML page to potentially escape the browser sandbox. The flaw is classified as CWE-693. While the official description indicates the possibility of sandbox escape, it does not confirm that the vulnerability has been successfully exploited in the wild, so the exact consequences for confidentiality, integrity, or availability remain indeterminate but could be severe if the escape is achieved.
Affected Systems
The flaw affects all Google Chrome installations that use ANGLE before version 150.0.7871.47, which includes the majority of current releases for Windows, macOS, Linux, and ChromeOS. The statement does not specify any operating‑system dependence, and there is no mention of Chrome builds that omit ANGLE, so it is inferred that any build that includes ANGLE is vulnerable.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical level of severity. The EPSS score of less than 1 % suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; a malicious web page accessed by a user could trigger the exploit. Because the flaw is a sandbox escape, successful exploitation would allow code to run outside the browser’s sandbox, potentially affecting the entire host system.
OpenCVE Enrichment
Debian DLA
Debian DSA