Impact
The vulnerability is an out‑of‑bounds write in Google’s ANGLE graphics library implementation within Chrome. An attacker can deliver a specially crafted HTML page that triggers this flaw, leading to the execution of arbitrary code with the privileges of the browser process. The flaw is identified as CWE‑787, confirming a memory corruption condition that can compromise confidentiality, integrity, and availability of the system.
Affected Systems
Affected systems are installations of Google Chrome running any version older than 148.0.7778.216. The issue exists across all platforms supported by the browser, as the ANGLE component is used for rendering graphics on Windows, macOS, and Linux.
Risk and Exploitability
The CVE has a CVSS score of 8.8, which corresponds to a High severity rating. While no EPSS score is supplied, the lack of a known exploit publicly does not diminish the risk; the attack requires only that the user load a malicious page, which is a common vector. Because the flaw exploits a native library, it can lead to execution of arbitrary code with the privileges of the browser process. The flaw is not yet in CISA’s KEV catalog, but it remains a top‑priority security issue for Chrome users.
OpenCVE Enrichment