Impact
A heap buffer overflow exists in the Codecs component of Google Chrome on Linux and ChromeOS. The flaw permits an attacker who has already compromised the renderer process to craft a malicious HTML page that can potentially escape the sandbox, enabling execution of arbitrary code outside the renderer environment.
Affected Systems
Google Chrome versions earlier than 149.0.7827.115 running on Linux or ChromeOS are affected.
Risk and Exploitability
Chromium classifies the vulnerability as High severity. No EPSS score is available and the issue is not listed in CISA’s KEV catalog. Exploitation requires an initial compromise of the renderer process, which in turn depends on other vulnerabilities or user interaction. Once the renderer is breached, the sandbox escape allows the attacker full access to the host system, making the potential impact critical.
OpenCVE Enrichment