Impact
A use‑after‑free error (CWE‑416) in the ANGLE graphics component of Google Chrome versions prior to 150.0.7871.46 can be triggered by a maliciously crafted HTML page loaded into the browser. When this page is processed, the flaw allows the attacker to escape Chrome’s sandbox and potentially gain host system privileges, enabling the reading or modification of files, installation of software, or other high‑impact actions outside the browser environment.
Affected Systems
All installations of Google Chrome that use the ANGLE renderer and run a build older than 150.0.7871.46 are affected.
Risk and Exploitability
The CVSS score of 9.6 indicates a severe remote sandbox escape. The EPSS score of less than 1% suggests that, as of now, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to host a malicious HTML page that a target user loads or views; upon processing that page, the use‑after‑free can be exercised, potentially delivering host‑level code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA