Impact
Use after free in ANGLE within Google Chrome before version 147.0.7727.138 allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox by loading a crafted HTML page. This vulnerability can lead to arbitrary code execution that breaks out of the browser environment, granting the attacker access to system resources and data.
Affected Systems
Google Chrome versions earlier than 147.0.7727.138 are affected. Only Chrome users on these older stable channel releases are impacted.
Risk and Exploitability
The Chromium severity is marked High. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first gain control of the renderer process, which limits the attack surface. Consequently, while the potential impact is severe, the likelihood of a successful attack is moderate to low without a prior renderer compromise.
OpenCVE Enrichment