Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
The bug is an integer overflow in the ANGLE library, which is responsible for translating OpenGL ES graphics calls. An attacker who has previously gained control over the renderer process (e.g., through a separate vulnerability) can prepare a specially crafted HTML page that triggers this overflow. As a result of incorrect integer value calculation, unpredictable memory behavior can occur, enabling escape from the boundaries of the isolated browser sandbox environment.
An attacker can escape the browser sandbox (sandbox escape), which potentially allows execution of malicious code outside the controlled Chrome environment and unauthorized access to the victim's operating system. With high ratings for confidentiality, integrity, and availability in the CVSS vector, consequences may include complete system takeover.
Google Chrome should be updated to version 149.0.7827.53 or later, in accordance with information published by the vendor in the references. The update is available through the browser's built-in update mechanism or the chromereleases.googleblog.com website.
Google Chrome in versions preceding 149.0.7827.53
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HGoogle Chrome
APPGoogle< 149.0.7827.53
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox