Impact
An inappropriate implementation in Chrome’s ANGLE graphics engine allows a remote attacker to potentially escape the browser sandbox by delivering a crafted HTML page. The CVE description belongs to CWE-693. The description indicates that escaping the sandbox could enable code execution beyond browser boundaries; however, the extent of impact on confidentiality, integrity or availability is not explicitly confirmed and the escape is described as a potential risk rather than a proven exploitation path.
Affected Systems
The flaw is present in all installations of Google Chrome that use the ANGLE implementation before version 150.0.7871.47. Based on the description, it is inferred that this includes current releases for Windows, macOS, Linux, and ChromeOS, unless the browser is built without ANGLE. The vulnerability does not depend on the operating system or device type.
Risk and Exploitability
The CVSS score of 9.6 indicates a high severity, while the EPSS score of less than 1% and absence from the CISA KEV list suggest a low chance of exploitation presently. The attack surface consists of a remote malicious web page that can be hosted by an adversary without requiring local privileges. This remote trigger makes the flaw attractive once discovered, warranting prompt patching and mitigation of untrusted web content.
OpenCVE Enrichment
Debian DLA
Debian DSA