Impact
A use‑after‑free flaw in the ANGLE component of Google Chrome allows a remote attacker to potentially escape the browser sandbox through a specially crafted HTML page. The vulnerability is a classic memory‑safety issue (CWE‑416) that could lead to execution of arbitrary code outside the sandbox, compromising system integrity and confidentiality.
Affected Systems
Google Chrome browsers running any version before 148.0.7778.216 are affected. The flaw exists in the ANGLE graphics library used by Chrome from the stable channel; newer releases have the fix applied.
Risk and Exploitability
The CVSS score of 8.3 indicates a very high risk level, confirming that the flaw can lead to a sandbox escape and potential arbitrary code execution outside the browser. The main attack vector is a maliciously crafted HTML page, allowing an attacker to trigger the attack by persuading a user to view or open the page in Chrome. The EPSS score is below 1%, indicating a very low probability of exploitation, but the high CVSS suggests the vulnerability is severe if exploited. The vulnerability is not listed in the CISA KEV catalog, so no immediate known exploitation is recorded, yet the remote nature and lack of local constraints make the attack feasible if not yet seen in the wild.
OpenCVE Enrichment