Impact
Based on the description, the likely attack vector is a crafted HTML page that triggers an out‑of The ANGLE component allows a renderer that is already compromised to escape Chrome’s sandbox. The vulnerability, identified as CWE‑787, could let an attacker run the host, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
All Chrome builds containing ANGLE versions prior to 150.0.7871.46 are vulnerable, including stable and other channels. Any installation that has not been updated to the patched version remains at risk.
Risk and Exploitability
Based on the description, the attacker would need to deliver a crafted HTML page to a compromised renderer. The CVSS score of 8.3 indicates high severity. The EPSS score is under 1%, showing a low, but non‑zero, probability of exploitation. The flaw is not included in CISA’s KEV catalog. Exploitation requires an attacker to inject malicious content into, after which the out‑of‑bounds write triggers a sandbox escape.
OpenCVE Enrichment
Debian DLA
Debian DSA