Impact
A read beyond the allocated buffer in Chrome’s media handling code on macOS could allow an attacker who has compromised the renderer process to read protected memory and potentially escape the sandbox. The flaw is a classic out-of-bounds read identified as CWE‑125. The impact is loss of isolation for the renderer, which could compromise the entire browser instance if leveraged further.
Affected Systems
Google Chrome on macOS prior to version 151.0.7922.72 is affected. Any older stable channel build of the browser should be considered at risk.
Risk and Exploitability
The EPSS score for this vulnerability is listed as less than 1 %, indicating a low probability of exploitation, and it does not appear in the CISA KEV catalog. The Chromium team rates the issue as medium severity. Exploitation requires a compromised renderer and a crafted HTML page, so the attack vector is likely remote via malicious web content embedded in a page that the user visits. If the renderer is already subverted, the flaw could be abused to break sandbox boundaries.
OpenCVE Enrichment
Debian DLA
Debian DSA