Impact
A buffer overflow in Chrome’s ANGLE component on Windows, affecting all releases prior to 153.0.8010.36, permits a remote attacker to execute arbitrary code beyond the browser sandbox. The flaw is a classic stack or heap overflow (CWE-122) that can be triggered by a crafted HTML page. The description notes that the impact is high in Chromium’s severity grading, indicating significant risk to confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is Google Chrome for Windows, specifically any installation running a version earlier than 153.0.8010.36. No other vendors or versions are listed.
Risk and Exploitability
The vulnerability is classified as high severity, with a CVSS score of 9.6, but the EPSS score is < 1% and it is not currently listed in CISA’s KEV catalog, suggesting a lower publicly verified exploitation probability. The likely attack vector is remote, via a maliciously constructed HTML page delivered over the network. Based on the description, it is inferred that an attacker can trigger the overflow by directing a user to the crafted page, leading to code execution outside the browser’s sandbox. Without known active exploits, the risk remains theoretical, yet the high Chromium severity indicates strong potential for exploitation if an attacker discovers or develops a payload.
OpenCVE Enrichment
Debian DLA
Debian DSA