Impact
Inappropriate handling within the ANGLE graphics layer of Google Chrome on macOS prior to version 148.0.7778.216 permits a remote attacker to execute arbitrary code within the browser sandbox by delivering a specially crafted HTML page. The flaw involves unsafe code evaluation (CWE-94), enabling the attacker to hijack control flow within the sandboxed environment.
Affected Systems
All Google Chrome builds for macOS released before 148.0.7778.216 are vulnerable; any earlier stable channel build on Mac falls within this scope.
Risk and Exploitability
The CVSS score is 8.8 and the vulnerability is not listed in CISA KEV, yet it is classified as high severity by Chromium. The EPSS score is <1%, indicating a very low probability of exploitation. Because the flaw is triggered by a crafted HTML page that can be served over the web, remote exploitation is possible and would execute code within the sandbox. While the sandbox may restrict some system interactions, the level of impact depends on the host’s sandbox configuration. Given the lack of known exploit tooling but the high severity classification, the overall risk remains significant for affected users.
OpenCVE Enrichment