Impact
A Chrome ANGLE graphics stack fails to properly validate untrusted input, allowing an attacker who has already compromised the renderer process to craft a specially malformed HTML page that can escape Chrome’s sandbox and execute arbitrary code with system‑level privileges. This Input Validation Failure (CWE‑20) undermines the browser’s confinement guarantees.
Affected Systems
Google Chrome browsers on any operating system that use ANGLE for rendering are affected, including Windows, macOS, Linux, and Chrome OS; versions older than 150.0.7871.46 are vulnerable, so all builds prior to that release remain susceptible.
Risk and Exploitability
Chromium rates the issue as High with a CVSS score of 8.3, while the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation; the vulnerability requires that the attacker already control the renderer process, limiting the attack surface; it is not listed in the CISA KEV catalog, so no widespread confirmed exploitation has been reported, yet the potential for system‑wide compromise makes it a serious risk for exposed or remote systems.
OpenCVE Enrichment
Debian DLA
Debian DSA