Impact
An out‑of‑bounds read occurs in ANGLE, a graphics abstraction layer used by Google Chrome. The vulnerability exists in Chrome versions prior to 151.0.7922.72. An attacker who has already compromised the renderer process can supply a specially crafted HTML page that may enable a sandbox escape. The weakness is listed as CWE‑125 and could lead to privilege escalation and full control over the system if the sandbox is bypassed.
Affected Systems
Google Chrome browsers running any build before 151.0.7922.72 are affected. The issue applies to all desktop platforms where ANGLE is used for rendering.
Risk and Exploitability
Based on the description, it is inferred that exploitation requires a remote attacker to first compromise the renderer process and then supply a crafted HTML page to trigger the out‑of‑bounds read that could lead to sandbox escape. The CVSS score of 8.8 indicates a high severity, and the EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA