Impact
An out‑of‑bounds write vulnerability exists in the video codec component of Google Chrome that can be triggered by a specially crafted video file. This buffer overflow (CWE‑787) may allow a remote attacker to escape the browser sandbox and potentially execute arbitrary code with higher privileges.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. Users running these versions, on any supported operating system, remain vulnerable until the patch is applied.
Risk and Exploitability
The Chrome team rates the issue as Medium severity. Exploitation requires the victim to open or render the malicious video file, representing a remote attack vector. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation yet, but the potential for sandbox escape creates a significant risk if the flaw is leveraged.
OpenCVE Enrichment