Impact
The ANGLE bug in the graphics abstraction layer used by Google Chrome is a type confusion (CWE-843) vulnerability. By delivering a specially crafted HTML page, a remote attacker can induce the browser to which may allow sandbox escape. The CVSS score of 9.6 demonstrates the potential to compromise system integrity by executing code beyond the restricted privileges of the browser process.
Affected Systems
Google Chrome browsers before version 150.0.7871.47 are affected. Only Google Chrome receives patches; no other vendors or products are known to be impacted.
Risk and Exploitability
A remote attacker can trigger the flaw by serving a specially crafted HTML page. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The CVSS score of 9.6 reflects a very high severity, such that successful exploitation would grant sandbox escape and privilege escalation beyond the browser process.
OpenCVE Enrichment
Debian DLA
Debian DSA