Impact
An integer overflow occurs in the font parsing logic of Google Chrome. A malicious HTML page containing tailored font data can trigger an out‑of‑bounds memory write. The overflow, classified as CWE‑472, may corrupt arbitrary memory, possibly leading to denial of service or other unintended execution paths. The description explicitly states that a remote attacker can deliver such a page.
Affected Systems
All Google Chrome desktop releases before version 150.0.7871.47 are affected. The vulnerability description does not mention mobile, so the impact appears limited to desktop builds. No other vendors or product families are listed.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS of < 1% shows a low current exploitation probability. The attack vector is likely remote, delivered through an HTML page that a user opens in an affected browser. No current evidence of exploitation and the vulnerability is not in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA