Impact
The vulnerability is an out-of-bounds write in the ANGLE graphics library used by Google Chrome on Windows. A crafted HTML page can trigger a write beyond the intended memory bounds, allowing the attacker to execute arbitrary code outside the browser sandbox. Chromium’s own assessment labels this issue as high severity, suggesting that successful exploitation could result in full system compromise.
Affected Systems
All Windows users running Google Chrome versions earlier than 153.0.8010.36 are affected. The September 2026 stable channel update contains the fix.
Risk and Exploitability
The flaw can be triggered remotely by delivering a malicious HTML document to a user’s browsing session. The EPSS score of < 1% indicates a very low, but non‑zero, likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that wide‑scale exploitation has not yet been observed. Nevertheless, the CVSS score of 9.6 highlights a high severity, and because arbitrary code may execute outside the sandbox, the risk to any user who visits an attacker‑controlled page before updating remains significant.
OpenCVE Enrichment
Debian DLA
Debian DSA