Impact
The vulnerability is a heap buffer overflow in the libyuv component of Google Chrome that exists on Windows systems running versions earlier than 150.0.7871.125. A malicious video file crafted by an attacker can cause the overflow, allowing the attacker to execute arbitrary code within the browser's sandbox. The flaw is classified as CWE-122 and CWE-787, indicating an uncontrolled allocation on the heap and an out‑of‑bounds write.
Affected Systems
Windows users who have Google Chrome installed before version 150.0.7871.125 are affected. No other operating systems or Chrome versions are mentioned in the CVE data, so the scope is limited to that specific Windows build and older Chrome releases.
Risk and Exploitability
The CVSS score of 8.8 signals a high‑severity remote code execution risk. The EPSS score of <1% indicates currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning there are no confirmed widespread attacks. An attacker would need to deliver a crafted video file to a user; if the file is opened or processed by Chrome, the attacker can run code inside the browser sandbox with the privileges of the current user. The exploitation remains confined to the browser context and does not automatically grant system‑level privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA