Impact
A flaw in the ANGLE component of Google Chrome stems from insufficient validation of untrusted input, an input‑validation weakness (CWE‑20). A crafted HTML page can bypass normal checks and potentially escape the browser sandbox to execute code with the host user’s privileges.
Affected Systems
All installations of Google Chrome older than version 150.0.7871.46, regardless of operating system, are affected; the issue is not related to browser extensions or third‑party plugins.
Risk and Exploitability
The CVSS score of 9.6 indicates severe risk, while the EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and exploitation would require delivery of a malicious HTML page, for which no public exploit is currently known.
OpenCVE Enrichment
Debian DLA
Debian DSA