Impact
The flaw lies in the ANGLE implementation of Google Chrome on macOS before version 151.0.7922.72 and allows a remote attacker to potentially escape the browser sandbox by serving a crafted HTML page. This issue is associated with integrity‑related weaknesses (CWE-501, CWE-693) and could lead to arbitrary code execution or privilege escalation, compromising confidentiality, integrity, and availability of the victim system.
Affected Systems
Google Chrome browsers running on macOS older than 151.0.7922.72 are affected. The vulnerability was identified in Chrome’s stable channel for Mac and applies to any installation that has not yet been updated to the patched release.
Risk and Exploitability
The CVSS score of 9.6 signals a high‑severity condition. The EPSS score of less than 1% and the fact that the issue is not listed in the CISA KEV catalog suggest that exploitation in the near term is unlikely. Nonetheless, the attack vector requires only that the victim open a malicious web page, which is a realistic scenario for social engineering or compromised sites. Given the severity, immediate remediation is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA