Impact
The vulnerability is an out‑of‑bounds write in the ANGLE graphics library used by Google Chrome. When a renderer process that was already compromised accesses a crafted HTML page, the memory corruption can break the sandbox isolation, allowing the attacker to execute code with higher privileges on the host. The flaw is classified as CWE‑787 and leads to a loss of isolation between browser content and the operating system, threatening confidentiality and integrity of the underlying system.
Affected Systems
All installed versions of Google Chrome older than 150.0.7871.46 are susceptible. This includes any desktop installation that has not yet been updated to this patched release.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability, while the EPSS score of <1% suggests a low but non‑zero probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog, meaning no publicly documented exploits have been observed. Exploitation requires an attacker to deliver a malicious HTML payload to a renderer that has already been compromised, making it a difficult but possible target in a well‑executed, directed attack.
OpenCVE Enrichment
Debian DLA
Debian DSA