Impact
The vulnerability is a heap buffer overflow in the ANGLE component of Google Chrome, identified by CWEs 120 and 122. It is triggered by loading a crafted HTML page, which can lead the browser to overwrite adjacent heap memory. If successfully exploited, this corruption could compromise the integrity of the browser process and potentially allow a malicious actor to manipulate execution flow, though a direct remote code execution has not been officially confirmed. The CVE is rated High in Chromium security severity.
Affected Systems
All Google Chrome installations running a version older than 146.0.7680.153 are affected across Windows, macOS, and Linux platforms. The vulnerability applies to any Chrome instance that processes the malicious HTML without the fix. Users should verify the version installed and apply the security build as soon as possible.
Risk and Exploitability
The base CVSS score of 8.8 signals a high‑severity vector with network access. The EPSS score is below 1 %, and the issue is not listed in the CISA KEV catalog. Exposing the browser to a malicious HTML page is the primary attack vector, requiring that the user visits or otherwise loads the content. While the risk of exploitation is considered low due to the prevailing low EPSS, the potential impact of heap corruption warrants active mitigation.
OpenCVE Enrichment
Debian DSA