Impact
An integer overflow occurs in the ANGLE graphics stack of Google Chrome, allowing a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The weakness is an integer overflow (CWE‑190).
Affected Systems
Google Chrome browsers on desktop platforms that are prior to version 151.0.7922.72 are affected. The vulnerability is specific to Chromium browsers using ANGLE for hardware-accelerated graphics.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote attacker serving a malicious HTML document that the victim must load, which is a typical web‑content based delivery for ANGLE. Adequate network segmentation, sandboxing, and timely patching are essential to mitigate this risk.
OpenCVE Enrichment
Debian DLA
Debian DSA