Impact
The vulnerability is an out-of-bounds write in ANGLE, Chrome's graphics abstraction layer on macOS. A malicious web page can trigger the renderer process to write beyond its allocated memory, allowing an attacker to escape the browser's sandbox and potentially gain system access. The weakness is classified as CWE‑787 and only requires that the victim visit a crafted HTML page; no further privileges or local access are needed.
Affected Systems
Google Chrome for macOS versions prior to 150.0.7871.46 are affected. Users running these older Chrome installations on macOS who open or render untrusted web content are at risk of a sandbox escape stemming from the ANGLE out-of-bounds write.
Risk and Exploitability
The CVSS score of 9.6 signals very high severity. The EPSS score of less than 1% indicates the probability of exploitation is low but not zero, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to persuade a victim to load a malicious web page containing a specially crafted HTML payload to trigger the vulnerability and potentially escape the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA