Impact
Out of bounds read in FFmpeg within Google Chrome allows a remote attacker to read sensitive data from process memory when parsing a specially crafted video file. The vulnerability is a buffer under‑read (CWE‑125) that can reveal confidential information such as credentials, encryption keys or user but does not provide code execution or denial of service.
Affected Systems
Google Chrome, all desktop builds using FFmpeg, specifically any installation older than version 150.0.7871.47 on the stable channel.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation to date. The CVSS score of 6.5 denotes medium severity, reflecting a moderate risk to confidentiality if exploited. The attack requires an attacker crafted video file, which could be achieved via a malicious web page or a compromised file download. The likely attack vector is remote access through a web browser, inferred from the description and not explicitly stated.
OpenCVE Enrichment
Debian DLA
Debian DSA