Impact
An integer overflow occurs in the ANGLE graphics layer of Google Chrome, allowing a maliciously crafted HTML page to corrupt heap objects. This flaw, reflected in the CWE‑190 and CWE‑472 identifiers, can lead to integrity violations within the browser process. The description explicitly states that the vulnerability can cause heap corruption, but it does not confirm execution of arbitrary code, so the impact is limited to corruption of internal data structures.
Affected Systems
All users who have Google Chrome versions earlier than 146.0.7680.153 on Windows, macOS, and Linux are affected. The flaw applies to any stable channel installation of Chrome that predates the March 2026 update released by Google.
Risk and Exploitability
The CVSS score of 8.8 marks this as high severity, while the EPSS score of less than 1% indicates a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack is most likely carried out through a remote browser interaction with a crafted HTML page; this inference is drawn from the description that the flaw can be triggered via a crafted page.
OpenCVE Enrichment
Debian DSA