Impact
A heap buffer overflow in the ANGLE component of Google Chrome before version 147.0.7727.101 enables a remote attacker to potentially escape the browser sandbox by serving a crafted HTML page. The vulnerability is classified as Critical by Chromium Security, indicating that exploitation could allow an attacker to gain elevated privileges and execute arbitrary code on the affected system.
Affected Systems
Google Chrome browsers that are older than 147.0.7727.101 are affected. Users running any of these releases on desktop platforms where ANGLE is utilized for rendering are at risk.
Risk and Exploitability
The CVE has a CVSS score of 9.6, indicating Critical severity, though the EPSS score is not available and it is not listed in CISA's KEV catalog, implying no publicly known exploits yet. The likely attack vector is remote, involving a maliciously crafted HTML page that the victim opens in Chrome. Exploitation requires the browser to process the page and trigger the vulnerable ANGLE code path, resulting in a sandbox escape. No special conditions beyond normal browsing are reported, suggesting that an attacker could attempt this from any internet-accessible location.
OpenCVE Enrichment
Debian DSA