Impact
A use after free vulnerability in ANGLE, the graphics abstraction layer used by Google Chrome on Windows, allows a remote attacker to trigger arbitrary code execution beyond the browser sandbox through a specially crafted HTML page. The flaw arises from improper memory deallocation, enabling the execution of malicious code with potentially full privileges on the affected system. This can lead to breach of confidentiality, integrity, and availability of the compromised machine.
Affected Systems
All Windows installations of Google Chrome running a version earlier than 153.0.8010.36 are affected. The vulnerability is limited to the Chrome browser on Windows; other platforms or later Chrome versions are not impacted.
Risk and Exploitability
Open‑based browsing provides the primary attack vector: a user who visits or opens a malcrafted HTML page can exploit the flaw. No public exploits are currently listed in CISA’s KEV catalog, and the EPSS score is < 1%, but the Chromium security team has rated the issue as High and assigned a CVSS score of 9.6 in the internal assessment. The combined severity and lack of mitigations in unpatched systems make this a high‑risk vulnerability that is relatively easy to exploit from a remote location.
OpenCVE Enrichment
Debian DLA
Debian DSA