Impact
A heap buffer overflow exists within the ANGLE graphics component used by Google Chrome on macOS. When a specially crafted HTML page is rendered, the overflow can potentially breach the browser sandbox, enabling an attacker to execute code with elevated privileges. The vulnerability carries a high severity rating in Chromium’s security assessment, indicating that successful exploitation could compromise the confidentiality, integrity, and availability of the affected system.
Affected Systems
Google Chrome versions prior to 148.0.7778.168 running on macOS are affected. The flaw is confined to the ANGLE component and does not impact other Chrome subsystems.
Risk and Exploitability
The CVSS score is 8.3, and the exploit prediction score (EPSS) is unavailable, but the vulnerability is not listed in the CISA KEV catalog. Despite the lack of public exploitation data, the nature of the heap overflow combined with a sandbox escape potential implies a high-risk scenario. Inferred from the description, the attack vector is remote, requiring a user to visit a maliciously crafted web page. Exploitation would likely need the user to have a vulnerable version of Chrome installed and active on a macOS machine.
OpenCVE Enrichment
Debian DSA