Impact
A type confusion flaw in ANGLE, the graphics engine used by Google Chrome, enables an attacker who has already compromised the renderer process to escape the browser sandbox and elevate privileges on the host system. The vulnerability, identified as CWE‑843, can lead to arbitrary code execution once the renderer context is subverted. Because the attacker must first gain code execution in the renderer, the final impact is a transition from a single‑user compromise to system‑wide control, enabling data theft or system compromise.
Affected Systems
Google Chrome browsers before version 151.0.7922.72 are affected; the defect exists across all platforms that ship the ANGLE graphics engine bundled with Chrome. No other vendors or versions are reported as impacted.
Risk and Exploitability
The CVSS score of 9.6 marks this issue as critical, while the current EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Successful exploitation requires an attacker to serve a specifically crafted HTML page that triggers the renderer code and then subvert the renderer process before the type confusion can be leveraged to escape the sandbox. The primary attack vector is a web‑based interaction delivering malicious content to the victim’s browser.
OpenCVE Enrichment
Debian DLA
Debian DSA