Impact
An out‑of‑bounds write occurs in the ANGLE graphics layer of Google Chrome, a component used to render web content. The flaw permits a remote attacker who has already managed to execute code inside the renderer process to escape the process sandbox and potentially run arbitrary code with elevated privileges. This constitutes a classic memory safety violation, CWE‑787, and directly threatens the confidentiality, integrity and availability of the host system.
Affected Systems
The vulnerability affects Google Chrome browsers with versions prior to 148.0.7778.216. Any installation of Chrome that has not received the update to 148.0.7778.216 or newer is potentially susceptible.
Risk and Exploitability
The advisory rates the issue as high severity, with an EPSS score of 0.00035, equivalent to less than 1%, indicating a very low but nonzero exploitation probability. The likely attack vector is that the attacker first needs to execute code within the renderer process, which could be achieved through a malicious web page or another lower‑level vulnerability, a scenario inferred from the description. Once that prerequisite is met, the out‑of‑bounds write can lead to a sandbox escape, giving the attacker full control of the host. The high severity rating signals that organizations should treat the flaw seriously. The CVSS score for this vulnerability is 8.2.
OpenCVE Enrichment