Impact
The vulnerability is a use‑after‑free flaw in ANGLE, the graphics layer employed by Google Chrome. A specially crafted HTML page can trigger the flaw, potentially allowing a remote attacker to escape Chrome’s sandbox. The weakness is captured by CWE‑416 and CWE‑825.
Affected Systems
Google Chrome users running versions prior to 151.0.7922.72 are affected. The issue applies to all platforms that utilize ANGLE, including Windows, macOS, and Linux.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a medium‑severity vulnerability. The EPSS score is less than 1%, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, the exploit likely requires a victim to load a crafted HTML page in the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA