Impact
Chrome’s media codec implementation allows an out‑of‑bounds read and a write when parsing specially crafted video files. The resulting heap corruption can be leveraged for code execution or other malicious activity, and the issue is cataloged as high severity by Chromium security.
Affected Systems
The vulnerability applies to all Google Chrome installations running a version earlier than 150.0.7871.115, regardless of platform, as it affects the core media codec code shared across desktop deployments.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact scenario, while the EPSS score of < 1% shows that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require the victim to open or view a malicious video file—either through a web page or by opening a local file—and could potentially lead to arbitrary code execution if the attacker can successfully trigger the heap corruption.
OpenCVE Enrichment
Debian DLA
Debian DSA