Impact
This vulnerability is an out‑of‑bounds write in the ANGLE graphics stack used by Google Chrome. An attacker who has already gained control of the renderer process can craft a malicious HTML page that triggers the write. If the write is executed, the attacker can escape the renderer sandbox and potentially execute code with higher privileges on the host system, leading to remote code execution.
Affected Systems
Affected systems are installations of Google Chrome with a version number older than 148.0.7778.216 running on any supported operating system where the ANGLE backend is enabled. The default component is the Chromium browser, roughly corresponding to the stable channel releases before that build.
Risk and Exploitability
The CVSS score is 8.2, and the EPSS score is unavailable; the vulnerability is not listed in the CISA KEV catalog. The only known exploitation path requires a compromised renderer process, but a crafted HTML page can provide the triggering payload. Because the vulnerability is high severity as noted by Chromium, the risk is significant for unpatched browsers that may still be exposed to malicious content.
OpenCVE Enrichment