Impact
An out‑of‑bounds write in ANGLE, the graphics abstraction layer used by Google Chrome, allows a remote attacker to potentially execute arbitrary code outside the browser sandbox with a crafted HTML page. The vulnerability is classified as high severity and could compromise the confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw exists in the Chrome browser on Windows machines, affecting all releases prior to version 152.0.7977.65. Users running the stable channel of Chrome with a version number lower than the mentioned release should verify and update immediately.
Risk and Exploitability
The EPSS score is below 1% and the CVSS score is 9.6, reflecting a very low likelihood of real‑world exploitation despite a critical severity. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to deliver a specially formed HTML document to the victim via a web page or malicious link; no proof of exploitation is published. The high impact together with lack of mitigations in the affected versions still indicate that the vulnerability poses a significant security risk.
OpenCVE Enrichment
Debian DLA
Debian DSA