Impact
Chrome versions before 149.0.7827.53 perform insufficient validation of untrusted input in their codec implementation. This allows a crafted video file to trigger an out-of-bounds memory write. The identified impact is a memory corruption that may lead to arbitrary code execution or a crash of the browser process, a concern for confidentiality and availability. It is inferred that such memory corruption could be exploited to gain code execution, but the description does not explicitly confirm this outcome.
Affected Systems
All users of Google Chrome running a version older than 149.0.7827.53 are affected. The vulnerability occurs in the Chrome media codec subsystem used to decode video files presented through the browser or media tags.
Risk and Exploitability
The exploit requires a remote attacker to supply a malicious video file that a vulnerable Chrome instance will play. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, but the CVSS score of 8.8 indicates high severity. Based on the description, it is inferred that a successful exploit could allow an attacker to execute code or crash the browser, potentially providing a foothold for further attacks. It is inferred that the attack vector is media input delivered over HTTP, email attachment, or local file system.
OpenCVE Enrichment
Debian DSA