Impact
The flaw exists in ANGLE, a core graphics engine of Chrome. Insufficient validation of untrusted input leads to a sandbox escape when a malicious HTML page is rendered. This CWE‑20 weakness can allow code execution beyond the browser’s sandbox, potentially compromising the host system. The abuse vector is a specially crafted page served to the victim.
Affected Systems
All Google Chrome releases before version 150.0.7871.46 are vulnerable. The issue targets the ANGLE component in the Chromium engine. Users running earlier Chrome on any platform are at risk until they upgrade to the fixed version or later.
Risk and Exploitability
The CVSS score of 9.6 designates it as a critical vulnerability, yet the EPSS score of < 1% indicates exploitation is presently unlikely. It is not listed in the CISA KEV catalog. An attacker could trigger the flaw by delivering a crafted HTML page to the victim, manipulating the browser’s rendering of external content. If successful, the sandbox would be bypassed, allowing execution of arbitrary code with the privileges of the Chrome process.
OpenCVE Enrichment
Debian DLA
Debian DSA