Impact
An integer overflow in the ANGLE graphics component of Google Chrome on macOS and Windows causes heap corruption when the browser processes a specially crafted HTML page. This flaw is identified as CWE-190 and CWE-472 and can lead to arbitrary code execution on the client system. The CVE description states that the vulnerability is exploitable by a remote attacker through crafted web content.
Affected Systems
All Chrome releases prior to version 148.0.7778.96 running on macOS or Windows are affected. The issue applies to the desktop stable channel and any build that incorporates the older ANGLE code base. Versions 148.0.7778.96 and later contain the patch that eliminates the integer overflow and its associated heap corruption.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score is under 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited exploitation in the wild. The likely attack vector is a remote attacker delivering malicious HTML content that forces the browser to trigger the overflow; once the heap is corrupted, the attacker can execute arbitrary code with the privileges of the user running Chrome. Given the potential impact and the low but nonzero probability of exploitation, timely remediation is strongly advised.
OpenCVE Enrichment
Debian DSA