Impact
Chrome versions before 149.0.7827.53 perform insufficient validation of untrusted input in their codec implementation. This allows a crafted video file to trigger an out‑of‑bounds memory write. The memory corruption could lead to arbitrary code execution or a crash of the browser process, posing a medium‑severity risk to confidentiality and availability.
Affected Systems
All users of Google Chrome running a version older than 149.0.7827.53 are affected. The vulnerability occurs in the Chrome media codec subsystem used to decode video files presented through the browser or media tags.
Risk and Exploitability
The exploit requires a remote attacker to supply a malicious video file that a vulnerable Chrome instance will play. No exploit probability is available via EPSS and the vulnerability is not listed in CISA’s KEV catalog, but the CVSS rating indicates medium severity. A successful exploit would allow an attacker to execute code or crash the browser, potentially providing foothold for further attacks. The attack vector is inferred to be media input delivered over HTTP, email attachment, or local file system.
OpenCVE Enrichment