Impact
A heap buffer overflow in the TabStrip component of Google Chrome allows a remote attacker, after convincing a user to perform specific UI gestures, to corrupt the browser’s heap. This corruption can lead to heap corruption and potentially other disruptive behavior, and is classified as a high severity flaw according to its CVSS score of 8.8. This flaw manifests as a heap buffer overflow (CWE-120) and a heap-based buffer overflow (CWE-122).
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. Users running these builds are at risk until the vulnerability is addressed.
Risk and Exploitability
The EPSS score is < 1% and it is not listed in the CISA KEV catalog, indicating limited current exploitation activity. The vulnerability requires a user to interact with a crafted HTML page and perform certain UI gestures, so exploitation would depend on social engineering. The CVSS score of 8.8 indicates high severity, underscoring the importance of timely mitigation. The vulnerability exploits buffer overflow weaknesses identified as CWE-120 / CWE-122.
OpenCVE Enrichment
Debian DSA