Impact
A flaw in Google Chrome’s ANGLE graphics engine fails to properly validate untrusted input, allowing a crafted HTML page to supply data that the renderer accepts. Based on the description, it is inferred that the attacker must have prior access to a compromised renderer process or exploit it via another vulnerability. The attacker can then leverage this weakness to escape the browser sandbox and execute code with system privileges, effectively achieving remote code execution. This flaw involves the weaknesses identified by CWE-1286 and CWE-20, which relate to improper input validation.
Affected Systems
All users of Google Chrome running versions before 151.0.7922.72, regardless of operating system, are vulnerable to this issue.
Risk and Exploitability
The CVSS score of 9.6 signifies a severe vulnerability. The EPSS score of less than 1% indicates that exploits in the wild are currently rare, and the vulnerability is not listed in CISA’s KEV catalog. However, based on the description, the attacker must first compromise the renderer process—most commonly by delivering a malicious HTML page—before they can escape the sandbox and gain elevated privileges on the host.
OpenCVE Enrichment
Debian DLA
Debian DSA