Impact
Improper input validation in ANGLE—a graphics abstraction layer used by Google Chrome—allows an attacker to trick the browser into accepting a specially crafted HTML page that can potentially execute arbitrary code outside the sandbox. This flaw arises from a failure to correctly check input boundaries, corresponding to CWE‑20. The impact is the possible compromise of system integrity and confidentiality when a user loads the malicious page.
Affected Systems
Google Chrome on macOS versions prior to 152.0.7977.65 is affected. A crafted HTML page presented to a user can trigger the vulnerability; no other platforms or extensions are mentioned.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while Chromium’s internal rating is medium, and the EPSS score is under 1%, indicating a low probability of exploitation. It is not listed in the CISA KEV catalog. The attack requires remote delivery of a fabricated HTML page, likely via a malicious website or phishing link, and relies on the browser parsing the page in a normal user session.
OpenCVE Enrichment
Debian DLA
Debian DSA