Impact
A use‑after‑free flaw in ANGLE allows an attacker who supplies a specially crafted HTML page to a Chrome user to run arbitrary code outside the browser sandbox. The vulnerability is a classic instance of invalid memory reference (CWE‑416). This flaw can be exploited to bypass the sandbox protections that otherwise isolate web content from the operating system.
Affected Systems
Google Chrome versions before 152.0.7977.65 are affected. The Chrome product is the only vendor‑specified affected product in the CNA data.
Risk and Exploitability
Chrome does not list an EPSS score and is not in the CISA KEV catalog, but Chromium reports the weakness as a High‑severity issue with a CVSS score of 9.6. Attackers would need to get a victim to open the crafted HTML page, which can be delivered from a malicious website or via a phishing link. The vulnerability permits code execution with the privileges of the browser process, potentially compromising the entire device if the attacker successfully escapes the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA