Impact
An integer overflow in the ANGLE graphics library of Google Chrome, discovered in versions prior to 151.0.7922.72, can allow a remote attacker who has already compromised the renderer process to escape the browser sandbox. The flaw, identified as CWE‑190, permits a crafted HTML page to corrupt internal data, potentially resulting in arbitrary code execution outside the sandbox. Because the vulnerability is within a privileged rendering engine, the impact is that an attacker could gain full system access from a malicious web page, aligning with a high severity level as reflected by a CVSS score of 9.6.
Affected Systems
Affected systems are users of Google Chrome up to and including version 151.0.7922.71. The issue does not affect Chrome 151.0.7922.72 or later, which includes the vendor‑provided fix. The vulnerability is scoped to the renderer process, which runs in a separate sandboxed environment from the browser core.
Risk and Exploitability
The CVSS score of 9.6 indicates that potential exploitation can provide local privilege escalation and remote code execution in the worst case. The EPSS score is less than 1%, suggesting that exploits are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must first be able to execute code within the renderer via a malicious HTML page; once that placeholder is achieved, the integer overflow can be triggered to escape the sandbox. Consequently, the risk level is high for environments that expose Chrome to uncontrolled web content, especially when remote users or web pages can trigger renderer code.
OpenCVE Enrichment
Debian DLA
Debian DSA