Impact
An integer overflow in libyuv, the image conversion library used by Google Chrome, occurs in Chrome versions older than 149.0.7827.103. The flaw is classified as CWE‑190 and is triggered when an attacker who has already compromised the renderer process feeds a specially crafted HTML page to the browser. The overflow can corrupt memory used by the renderer, allowing the attacker to break out of the Chrome sandbox and obtain code‑execution privileges on the underlying operating system.
Affected Systems
Google Chrome browsers running any operating system (Windows, macOS, Linux) with versions prior to 149.0.7827.103 are affected.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity, but the EPSS score of <1% suggests a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Attackers require the ability to deliver malicious content to the compromised renderer; once the integer overflow is triggered, sandbox escape can lead to full system compromise. The risk is significant for environments that allow untrusted content to be rendered in Chrome.
OpenCVE Enrichment
Debian DSA