Impact
A use‑after‑free flaw in the ANGLE graphics subsystem of Google Chrome can be triggered by a crafted HTML page. The vulnerability, defined as CWE‑416, allows an attacker to access memory that has already been freed, potentially leading to a sandbox escape and elevation of code execution privileges beyond the browser sandbox. The CVSS score of 9.6 reflects the high severity of this exploitation path.
Affected Systems
Google Chrome builds prior to version 150.0.7871.46 are affected. This includes all stable channel releases where the ANGLE component has not yet incorporated the patch. Users running any of these versions before the specified update are potentially vulnerable.
Risk and Exploitability
The flaw can be exploited remotely from any web page received over the network. Based on the description, it is inferred that any web page served by an untrusted source can potentially trigger the vulnerability, although this specific detail is not given explicitly in the CVE entry. The EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the possibility of a sandbox escape warrants immediate remedial action.
OpenCVE Enrichment
Debian DLA
Debian DSA