Impact
This vulnerability arises from improper validation of an array index within the ANGLE graphics driver of Google Chrome. A crafted HTML page can cause Chrome to access memory outside the intended bounds, potentially allowing a remote attacker to run arbitrary code that bypasses the browser sandbox. The weakness is a classic array index validation flaw, listed as CWE-129, and could lead to full system compromise if exploited successfully.
Affected Systems
Google Chrome browsers prior to version 153.0.8010.36 are affected. All installations running these or earlier versions are vulnerable to attacks launched via malicious web content.
Risk and Exploitability
Chromium indicates a high severity level for this issue (CVSS score of 9.6). EPSS score indicates an exploitation probability of less than 1%, and the vulnerability is not listed in the CISA KEV catalog, so the public exploitation probability remains uncertain. The likely attack vector is a remote attacker delivering a malicious HTML page that abuses ANGLE; no privileged local access or additional conditions are required once the page is rendered by the victim’s browser.
OpenCVE Enrichment
Debian DLA
Debian DSA