Impact
The vulnerability is an out‑of‑bounds write in ANGLE used by Google Chrome on Windows platforms prior to version 152.0.7977.65, a flaw identified as CWE‑787. A maliciously crafted HTML page can cause memory to be read or overwritten beyond intended bounds, potentially breaking sandbox isolation and enabling arbitrary code execution inside the browser. Chromium security reviewers have classified this flaw as High severity.
Affected Systems
Affected systems are installations of Google Chrome running on Windows with versions older than 152.0.7977.65. The flaw resides in the ANGLE rendering engine that processes HTML content delivered to all Windows users of Chrome.
Risk and Exploitability
The CVSS score is 8.8, indicating a high impact. The EPSS score is <1%, suggesting a low overall exploitation probability at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The most realistic attack vector involves a remote attacker delivering or embedding a specially crafted HTML page via a website or local file that is opened by the user in an affected Chrome instance. If leveraged successfully, the out‑of‑bounds write can escape the rendering sandbox, giving the attacker full control of the browser process and the possibility of broader system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA