Impact
A use‑after‑free (CWE‑416) flaw in the ANGLE graphics backend of Google Chrome can be triggered by a malicious, crafted HTML page loaded into the browser. When this page is processed, the error allows the attacker to break out of Chrome’s sandboxing mechanism, potentially gaining host‑level outside the browser environment.
Affected Systems
All installations of Google Chrome that use the ANGLE renderer and run a build older than 150.0.7871.46 are affected.
Risk and Exploitability
The CVSS score of 9.6 indicates severe remote sandbox escape risk. The EPSS score of less than 1% suggests a low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a remote attacker delivering a crafted HTML page that the victim opens or views, which then feeds escape the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA