Impact
A use‑after‑free within Chrome’s ANGLE graphics engine can be triggered by a crafted HTML page, allowing an attacker to escape the browser sandbox and potentially execute arbitrary code with the privileges of the user session; the vulnerability is classified as CWE‑416 and has been designated critical by Chromium.
Affected Systems
All installations of Google Chrome older than 150.0.7871.46, including version 150.0.7871.45 and earlier, on any operating system that uses ANGLE (Windows, macOS, Linux, Chrome OS) are affected; any device that can browse untrusted HTTP/HTTPS content may process the malicious payload.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical risk, while the EPSS score of less than 1 % indicates a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploitation. Based on the description, it is inferred that the attack vector is remote, generally originating from a malicious web page accessed by the user, and successful exploitation would break out of the browser sandbox and allow code execution within the context of the current user.
OpenCVE Enrichment
Debian DLA
Debian DSA