Impact
The vulnerability is an out‑of‑bounds write in the ANGLE graphics stack used by Google Chrome on Windows before version 152.0.7977.65. A crafted HTML page can corrupt memory inside the sandbox process, potentially allowing an attacker to execute arbitrary code. The weakness is identified as CWE‑787 and is rated high severity by Chromium’s internal scoring.
Affected Systems
Google Chrome installations running on Windows that have not yet been updated to version 152.0.7977.65 or later are affected. The ANGLE component of these releases is the point of exploitation.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of exploitation in the wild, but the CVSS score of 8.8 classifies the vulnerability as high. The vulnerability is not listed in the CISA KEV catalog. A remote attacker could host or deliver a malicious webpage containing a crafted HTML document, which, when rendered by a vulnerable browser, could trigger the out‑of‑bounds write, corrupt sandbox memory, potentially escape the sandbox, and execute arbitrary code. The likely attack vector is the delivery of a crafted HTML page over the network to a user’s browser, inferred from the description. Despite the low EPSS, the high impact of arbitrary code execution warrants immediate remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA