Impact
An out‑of‑bounds write in ANGLE, triggered by a crafted HTML page, allows a remote attacker to execute arbitrary code outside Chrome’s sandbox. The flaw is a classic memory corruption vulnerability—CWE‑787—providing the attacker with the ability to take control of the browser process.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 on all platforms are affected. The issue is present on desktop builds and is active in the stable channel until the update is installed.
Risk and Exploitability
The vulnerability carries a high severity rating, with a CVSS score of 9.6. It requires only that a malicious web page be loaded in the user’s browser, which is a realistic condition for many users. The EPSS score is less than 1% and the flaw is not listed in the CISA KEV catalog, yet the availability of exploit code and the lack of sandbox escape mitigations keep the risk significant.
OpenCVE Enrichment
Debian DLA
Debian DSA