Impact
A buffer overflow exists in the ANGLE component of Google Chrome before version 152.0.7977.65. An attacker can deliver a specially crafted HTML page that triggers the overflow, allowing execution of arbitrary code outside the browser sandbox. This flaw represents a serious confidentiality and integrity threat, giving the attacker full control over the system that runs the vulnerable browser. The vulnerability is annotated with CWE‑122, indicating a classic heap‑based buffer overflow weakness.
Affected Systems
All Chrome installations using a version earlier than 152.0.7977.65 are impacted. This includes every platform and operating system supported by Chrome, regardless of architecture, because the flaw is in the core rendering engine ANGLE. Users who have not upgraded to the latest stable channel are at risk.
Risk and Exploitability
The description states that a remote attacker can exploit the issue via a crafted HTML page; no additional prerequisites are mentioned, so the attack vector is likely a web‑based drive‑by scenario. The flaw carries a CVSS score of 9.6. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, but its high severity and the ability to escape the sandbox suggest that exploitation is plausible and could have wide consequences.
OpenCVE Enrichment
Debian DLA
Debian DSA