Impact
The flaw is a heap buffer overflow in the ANGLE graphics driver within Google Chrome, allowing a remote attacker to execute arbitrary code through a crafted HTML page. This vulnerability, classified as CWE‑122 and CWE‑787, permits the attacker to run code with the privileges of the browser process, potentially compromising confidentiality, integrity, and availability on the victim’s machine.
Affected Systems
The issue affects Google Chrome on macOS for versions prior to 146.0.7680.178. Other operating systems may be affected as listed by the broader CPE, but the advisory explicitly references Mac. Users running the deprecated Chrome release on macOS should be notified that their browser is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS of less than 1 % suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, so no known large‑scale attacks have been reported yet, but the remote code execution nature warrants prompt attention. Attackers are able to trigger the defect simply by loading a malicious HTML page accessed over the network.
OpenCVE Enrichment
Debian DSA