Impact
An out‑of‑bounds write in ANGLE, the graphics abstraction layer used by Google Chrome, allows a maliciously crafted HTML page to write beyond the bounds of a buffer during rendering. This memory corruption can break the browser’s sandbox isolation and potentially let an attacker execute arbitrary code with the same privileges as the user's Chrome process. The flaw is classified as high severity by Chromium’s security team and can lead to full system compromise if exploited.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. The vulnerability exists in all builds that ship the older ANGLE implementation, regardless of operating system.
Risk and Exploitability
The likely attack vector is remote delivery of a malicious HTML document that triggers the buffer overrun. No publicly available exploit code is documented, and the EPSS score is < 1%, indicating a very low exploitation probability. The CVSS score of 9.6 indicates a critical threat, but the high severity classification also suggests that exploitation could be possible given the vulnerability. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment
Debian DLA
Debian DSA