Impact
A use‑after‑free bug in ANGLE, the graphics abstraction layer used by Google Chrome, can be triggered by a crafted HTML page loaded from the Internet. It may allow a remote attacker to escape the renderer sandbox. The flaw is enumerated as CWE‑416 and can compromise the confidentiality, integrity, and availability of affected systems.
Affected Systems
The vulnerability impacts Google Chrome on all platforms that use ANGLE, specifically versions earlier than 151.0.7922.72. Users running older Chrome releases are susceptible.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity, while the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack requires only a malicious web page and can lead to sandbox escape, making the threat realistic for consumers who browse the web.
OpenCVE Enrichment
Debian DLA
Debian DSA