Impact
A use‑after‑free vulnerability in the ANGLE graphics layer of Google Chrome allows a remote attacker to run code outside the browser sandbox by serving a specially crafted HTML page. This flaw can lead to full compromise of the host system, as the attacker gains the privileges of the user running the browser.
Affected Systems
The vulnerability affects Google Chrome versions earlier than 152.0.7977.65. Only the official Chrome browser is listed; no other vendors are impacted.
Risk and Exploitability
The CVSS score for this vulnerability is 9.6, indicating a critical risk level. No EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. Attackers would need to deliver a malicious HTML page to unsuspecting users, making web‑based social engineering the most likely vector.
OpenCVE Enrichment
Debian DLA
Debian DSA