AI analysis
Google Chrome on Windows prior to 153.0.8010.36 contains a buffer overflow (CWE-122) in ANGLE, the graphics shader-translation layer Chrome uses for WebGL and GPU rendering. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, causing memory corruption in the ANGLE component. Successful exploitation allows the attacker to execute arbitrary code outside the Chrome sandbox, meaning code runs with broader host-level privileges rather than being confined to the browser renderer. All Chrome users on Windows running affected builds are exposed; the advisory scope does not state impact for other operating systems. The flaw carries a Chromium 'High' severity rating and a critical CVSS 9.6 score; EPSS currently estimates only a 0.3% chance of exploitation in the next 30 days and it is not in CISA KEV, but release coverage of Chrome 153 reports a zero-day exploited in the wild, though public confirmation tying that activity to this specific bug is limited.
What to do: Update Chrome on Windows to 153.0.8010.36 or later (via chrome://settings/help or your managed update channel); the fix ships in Chrome 153, which includes 230 security fixes. Since the bug is triggered via web content and exploitation outside the sandbox is reported, prioritize patching internet-facing user fleets and confirm no clients remain on pre-153 builds.
Affected
| google chrome | Chrome on Windows prior to 153.0.8010.36 |
Estimated exposure
massbillions of users (Chrome has roughly 3+ billion users; Windows is its largest desktop platform) — Chrome holds roughly 65% global browser market share across an estimated 3-4 billion users, and Windows is its largest desktop platform, so every Windows user not yet on 153.0.8010.36 is plausibly affected.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.