Impact
An integer overflow vulnerability in the ANGLE component of Google Chrome on macOS and Windows platforms allows a malicious attacker to corrupt the heap. This flaw can be triggered by loading a specially crafted HTML page, potentially enabling the execution of arbitrary code on the affected machine. The weakness is classified as CWE-472, which indicates an integer overflow leading to buffer overread or underwrite. The impact is severe, as any user who visits a malicious page could be compromised without their knowledge.
Affected Systems
Google Chrome browsers running on macOS or Windows versions older than 148.0.7778.96 are affected. The vulnerability applies to the desktop stable channel and any other release built on the same code base. Users on newer Chrome releases that include the ANGLE patch are not vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. While the EPSS score is not available and the issue is not listed in CISA’s KEV catalog, the nature of the flaw—heap corruption triggered by web content—suggests that exploitation is plausible in real‑world scenarios. Attackers would need to convince a user to load a malicious HTML page; once processed by the buggy ANGLE library, they could achieve code execution on the client system.
OpenCVE Enrichment
Debian DSA