Impact
A flaw in Chrome’s media codecs permits an out‑of‑bounds read (CWE‑125) and write (CWE‑787) when parsing certain video files. The heap corruption that results can be leveraged for code execution or other malicious activity, and the Chromium team has rated the issue as high severity.
Affected Systems
The vulnerability affects all installations of Google Chrome running a version prior to 150.0.7871.115. The official hotspot for fixes is the stable desktop channel, so any desktop Chrome user who has not yet upgraded beyond that baseline remains exposed.
Risk and Exploitability
The CVSS score of 8.8 signals a high impact scenario, while the EPSS score of < 1% indicates that exploitation opportunities are presently rare. No public exploits have been reported, but the heap corruption mechanics make this a potential target for a determined adversary. Exploitation would likely require the victim to open or view a maliciously crafted video file, either through a web page or a local file. The CVE is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA