Impact
An integer overflow in the libyuv library used by Google Chrome before version 149.0.7827.103 allows a remote attacker who has already compromised the renderer process to trigger a sandbox escape via a crafted HTML page. The flaw, classified as CWE‑472, can give the attacker code execution outside the browser sandbox, potentially compromising system resources.
Affected Systems
All desktop builds of Google Chrome running versions prior to 149.0.7827.103 are affected. This includes Windows, macOS, and Linux releases that rely on libyuv for image processing.
Risk and Exploitability
The vulnerability requires an attacker to first compromise the renderer process through other means, such as exploiting another vulnerability or conducting social engineering. Once that condition is met, the integer overflow can be triggered by a malicious HTML page. The EPSS score is < 1%, and the CVSS score of 8.3 indicates moderate to high severity. The vulnerability is not listed in CISA's KEV catalog, but the Chromium severity label of Critical indicates a high risk if the conditions are satisfied.
OpenCVE Enrichment