Impact
A type confusion flaw exists in the ANGLE graphics stack of Google Chrome before version 152.0.7977.65. The flaw can be triggered by an attacker who hosts a specially crafted HTML page and can lead to execution of arbitrary code outside the browser sandbox. The security severity is rated high, indicating that exploitation could grant the attacker significant privileges over the host system.
Affected Systems
Google Chrome browsers running any release older than 152.0.7977.65 are vulnerable. All users of these versions who view untrusted web pages are at risk.
Risk and Exploitability
The vulnerability is remotely exploitable via a crafted HTML page delivered over the network. The EPSS score of 0.00381 indicates a very low probability of exploitation, but the high severity, with a CVSS score of 9.6, suggests a substantial risk to affected users. No mitigations are available other than applying the official patch, so the potential impact remains significant until the update is deployed.
OpenCVE Enrichment
Debian DLA
Debian DSA