Impact
Use after free in ANGLE within Google Chrome before version 147.0.7727.138 allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox by loading a crafted HTML page. This vulnerability can lead to arbitrary code execution that breaks out of the browser environment, granting the attacker access to system resources and data.
Affected Systems
Google Chrome versions earlier than 147.0.7727.138 are affected. Only Chrome users on these older stable channel releases are impacted.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity. The Chromium severity is marked High. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first gain control of the renderer process, which limits the attack surface. Consequently, while the potential impact is severe, the likelihood of a successful attack remains low without a prior renderer compromise.
OpenCVE Enrichment
Debian DSA