Impact
An integer overflow in Google Chrome allows a specially crafted HTML page to cause the browser to write data beyond intended memory bounds. This out‑of‑bounds memory write can corrupt memory, leading to denial of service or other unintended behavior. The vulnerability exploits the numeric overflow in handling font metrics and is classified as CWE‑472.
Affected Systems
Google Chrome desktop builds released before version 150.0.7871.47 are affected; it is currently unspecified whether mobile or other platform builds are impacted. The parsing code in the desktop release of Chrome.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The likely attack vector is a remote attacker delivering a crafted HTML page that includes malicious font data, as inferred from the description of the vulnerability. It is inferred from the lack of public reports that active exploitation has not yet been observed. The resulting out‑of‑bounds write could corrupt memory, potentially leading to denial of service or other unintended behavior.
OpenCVE Enrichment
Debian DLA
Debian DSA