Impact
This vulnerability is an out of bounds write in the ANGLE graphics layer of Google Chrome that can be triggered by a maliciously crafted HTML page. The flaw allows a remote attacker to break out of the renderer process sandbox and execute arbitrary code on the host system. The weakness is a classic buffer overrun listed as CWE-787, and the potential for full system compromise exists if the user visits the malicious page.
Affected Systems
The issue affects all versions of Google Chrome released before build 152.0.7977.65. Therefore any user running Chrome 151.x or earlier on Windows, macOS, or Linux is vulnerable. The problem is present in the stable channel and does not affect the Canary or Beta channels if they are already updated. Users of the new release 152.0.7977.65 and later are not impacted.
Risk and Exploitability
Although the official Chromium security severity is Medium, the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread exploitation campaigns have been observed yet. The CVSS score of 8.8 reflects the high severity of the remote code execution flaw. However, the remote code execution nature of the flaw means that an attacker who can serve a crafted HTML page is likely able to compromise the victim's machine. The exploit would require the user to visit the malicious page, so social or phishing vectors remain the primary attack medium until proof of penetration tools appear.
OpenCVE Enrichment
Debian DLA
Debian DSA