Impact
An out‑of‑bounds write has been discovered in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw allows a remote attacker, after having compromised the browser’s renderer process, to potentially escape the renderer sandbox and gain higher privileges on the host system. The weakness is a classic buffer overrun, classified as CWE‑787.
Affected Systems
The vulnerability affects all versions of Google Chrome released before 150.0.7871.182. It is tied to the ANGLE component used throughout Chrome’s rendering pipeline. Users running any affected Chrome edition on desktop platforms (Windows, macOS, Linux) are at risk if an attacker can serve a malicious web page that triggers the overflow.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity, while the EPSS score of less than 1 % indicates a currently low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the attacker first gain control of the renderer process, or, by social engineering, trigger the out‑of‑bounds write with a crafted HTML page delivered through a compromised or malicious website.
OpenCVE Enrichment
Debian DLA
Debian DSA