Impact
A heap buffer overflow in the TabStrip component of Google Chrome allows a remote attacker, after convincing a user to perform specific UI gestures, to corrupt the browser’s heap. This corruption can lead to arbitrary code execution or other disruptive behavior, and is classified as a medium severity flaw by Chromium.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are affected. Users running these builds are at risk until the vulnerability is addressed.
Risk and Exploitability
The EPSS score is not available and no listing in the CISA KEV catalog is reported, indicating limited current exploitation activity. The vulnerability requires a user to interact with a crafted HTML page and perform certain UI gestures, so immediate exploitation is possible but depends on social engineering. The CVSS score has not been provided, but the flaw’s medium severity suggests a notable risk if leveraged.
OpenCVE Enrichment