Impact
The vulnerability is an out‑of‑bounds read and write in ANGLE, a graphics abstraction layer used by Chrome. The flaw allows a remote attacker who can deliver a crafted HTML page to a victim to potentially escape the browser sandbox and execute code with elevated privileges. The weakness is identified as CWE‑125, which represents memory safety errors such as buffer overreads and overwrites.
Affected Systems
Google Chrome browsers prior to version 151.0.7922.72 are affected. No additional vendor or product variants are noted.
Risk and Exploitability
The CVSS score of 9.6 indicates a high‑severity risk, but the EPSS score of less than 1% suggests a low probability of widespread exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a malicious web page that a user visits, leveraging the browser’s rendering engine to trigger the out‑of‑bounds memory access and achieve sandbox escape.
OpenCVE Enrichment
Debian DLA
Debian DSA