Impact
The vulnerability is a use‑after‑free flaw in the ANGLE graphics library used by Google Chrome. When a renderer process has been compromised, a crafted HTML page can trigger the bug, allowing the attacker to escape the renderer sandbox and potentially execute arbitrary code on the host machine. The flaw is rated high severity by Chromium.
Affected Systems
Affected are installations of Google Chrome prior to version 148.0.7778.216. Any user of those older builds is potentially susceptible to this exploit if an attacker can deliver a malicious HTML page to the victim’s browser.
Risk and Exploitability
Because the bug requires a compromised renderer process, the attacker must first gain renderer access—often through other web‑based vectors or social engineering. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but its CVSS score of 9.0 and the potential for sandbox escape make it a serious risk. No countermeasures are mentioned beyond the official patch, so the safest approach is to update.
OpenCVE Enrichment