Impact
A heap-based buffer overflow exists in the WebRTC component of Google Chrome. The flaw allows a remote attacker who delivers a specially crafted HTML page to execute arbitrary code inside the browser sandbox. The problem is rooted in unchecked memory bounds handling (CWE‑122).
Affected Systems
Google Chrome versions preceding 149.0.7827.155 are affected.
Risk and Exploitability
The CVSS score of 8.8 marks this issue as high severity, but its EPSS of less than 1% suggests low exploitation probability at present. It is not listed in CISA’s KEV catalog. The attack requires a victim to visit or otherwise trigger the malicious page, after which the attacker can run code confined to the browser sandbox, potentially leveraging additional escape mechanisms if present.
OpenCVE Enrichment