Impact
The vulnerability resides in ANGLE, a core graphics component of Google Chrome. The flaw stems from insufficient validation of untrusted input, allowing a remote attacker to potentially escape the browser sandbox through a specially crafted HTML page. This is a sandbox escape vulnerability classified as CWE‑20: Improper Input Validation.
Affected Systems
All versions of Google Chrome prior to 150.0.7871.46 are affected. The CVE description does not explicitly state whether later releases contain a fix, so users should verify against vendor updates.
Risk and Exploitability
The CVSS score of 9.6 places this vulnerability in the critical range, while the EPSS score of <1% indicates a low probability of real‑world exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The CVE description indicates that a crafted HTML page could trigger the flaw, potentially allowing the attacker to escape the browser sandbox and execute code beyond the browser’s confined environment.
OpenCVE Enrichment
Debian DLA
Debian DSA