Impact
An out‑of‑bounds write in the ANGLE graphics engine of Google Chrome can be triggered by a maliciously crafted HTML page. If the attacker has already managed to compromise the renderer process, the flaw can be used to escape Chromium’s sandbox and execute arbitrary code on the machine. The weakness is classified as CWE‑787.
Affected Systems
All users of Google Chrome versions prior to 151.0.7922.72 are affected, regardless of operating system, when browsing the web or opening local files that include the crafted HTML content.
Risk and Exploitability
The CVSS score of 9.6 denotes critical severity, yet the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a user visiting a malicious website or opening a locally stored HTML file that includes the exploit. The attacker must first gain a foothold in the renderer process, after which the out‑of‑bounds write can be used to escape the sandbox and elevate privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA