Impact
A heap buffer overflow in the Media component of Google Chrome, affecting versions prior to 149.0.7827.53, allows a remote attacker who persuades a user to perform specific UI gestures to trigger a crafted HTML page that can execute arbitrary code inside a sandbox. The flaw is a classic buffer overrun (CWE‑122) and was classified as High severity by Chromium. The impact is the execution of code with at least sandboxed privileges, which could be leveraged further to escape or gain persistence if exploited effectively.
Affected Systems
All users running Google Chrome Stable on desktop platforms below version 149.0.7827.53 are susceptible. This includes Chrome on Windows, macOS, and Linux operating systems. Version information is limited to the major release number; users should verify they are below the patched release 149.0.7827.53.
Risk and Exploitability
The CVSS score is 7.5, which is considered High, reflecting a high likelihood of exploitation once the user engages with the malicious content. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known mass exploitation yet. Vulnerability exploitation requires a user to interact with a crafted HTML page, typically by visiting a malicious website or following a social‑engineering cue that initiates the required UI gestures. Once triggered, the overflow can lead to arbitrary code execution within the sandboxed context.
OpenCVE Enrichment