Impact
An out-of-bounds write in ANGLE, the graphics component of Chrome, allows a remote attacker to craft a malicious HTML page that, when rendered on Windows, can escape the browser sandbox and execute arbitrary code. This high-severity flaw is a classic memory-corruption vulnerability that could compromise system confidentiality, integrity, or availability.
Affected Systems
The flaw affects Google Chrome running on Windows. No other operating systems or Chrome products are explicitly listed as impacted.
Risk and Exploitability
The CVSS score of 9.6 signals critical risk. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is a remote attacker delivering a crafted web page to a user. If exploited, the attacker could gain full system control by breaking out of the browser sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA