Impact
A vulnerability exists in the ANGLE component of Google Chrome in all releases before 150.0.7871.46. It results from insufficient validation of untrusted input and is classified as an input validation flaw (CWE‑20). A crafted HTML page can bypass normal input checks and enable a sandbox escape, potentially allowing code execution with the privileges of the host user.
Affected Systems
The flaw affects all installations of Google Chrome older than version 150.0.7871.46, regardless of operating system. It is unrelated to extensions or third‑party plugins.
Risk and Exploitability
The CVSS score of 9.6 indicates severe risk. The EPSS score of less than 1 % implies a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires a crafted HTML page, which could be delivered via an untrusted website. No public exploit is known at this time, so while the potential impact is high, the probability of current exploitation remains limited.
OpenCVE Enrichment
Debian DLA
Debian DSA