Impact
The vulnerability manifests as an out‑of‑bounds write in ANGLE, Chrome’s graphics abstraction layer on macOS. The flaw allows a malicious web page to cause the renderer process to write beyond its allocated buffer, potentially breaking out of the renderer sandbox and gaining arbitrary code execution on the host system. This weakness is classified as CWE‑787.
Affected Systems
Google Chrome for macOS versions earlier than 150.0.7871.46 are affected. Users running these older Chrome installations who open or render untrusted web content are at risk of a sandbox escape stemming from the ANGLE out‑of‑bounds write.
Risk and Exploitability
The CVSS score of 9.6 indicates very high severity. The EPSS score of less than 1% denotes a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to convince a victim to load a crafted HTML page containing a specially constructed payload. Based on the description, it is inferred that no special privileges beyond the normal user level are required for exploitation; the attacker does not need local access or elevated rights.
OpenCVE Enrichment
Debian DLA
Debian DSA