Impact
A heap buffer overflow occurs in the Video component of Google Chrome before version 149.0.7827.53. If an attacker serves a specially crafted HTML page that compels the renderer process to overflow, the overflow can trigger a sandbox escape. This vulnerability is rated high severity by Chromium.
Affected Systems
The vulnerability affects Google Chrome on desktop systems running any stable channel release older than 149.0.7827.53. Versions 149.0.7827.53 and later contain the fix and are not susceptible to the overflow.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. An EPSS score is not available and the flaw is not listed in the CISA KEV catalog. The attack requires compromise of the renderer process, implying a higher effort. The potential for sandbox escape poses significant risk for users of affected Chrome versions.
OpenCVE Enrichment