Impact
The vulnerability is an out‑of‑bounds write inside ANGLE, the graphics abstraction layer used by Chrome. A carefully crafted HTML page can push data beyond the intended buffer bounds, potentially allowing a remote attacker to execute code outside the browser sandbox. The attack could result in full system compromise if the sandbox is bypassed.
Affected Systems
Affected systems are Google Chrome desktop users running any version prior to 152.0.7977.65. This includes the stable channel releases available as of August 2026. The issue is disclosed by Google and referenced in the Chrome release notes and Chromium issue tracker.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity. The EPSS score of <1% indicates a very low exploitation probability, but the lack of a CISA KEV listing does not reduce the risks: remote code execution through a crafted web page remains a serious threat. The expected attack vector is a malicious web page served to a user; the attacker must only get the user to load the page. Immediate patches are recommended due to this remote execution potential.
OpenCVE Enrichment
Debian DLA
Debian DSA