Impact
Google Chrome contains a heap buffer overflow in the libvpx video decoding library that can be triggered by a specially crafted HTML page. The overflow can corrupt heap data, which an attacker may leverage to execute arbitrary code, potentially compromising confidentiality, integrity, and availability of the affected system. The CVSS base score of 8.8 reflects the high severity of this vulnerability.
Affected Systems
The flaw affects all installations of Google Chrome prior to version 144.0.7559.132 across supported operating systems, including Windows, macOS, and Linux. Any user who visits a malicious web page or opens a crafted HTML attachment while running an affected Chrome build is at risk.
Risk and Exploitability
The stored EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is a remote attacker delivering a malicious HTML page to a user via a compromised or deceptive website, exploiting the overflow while the browser parses the page. This would allow execution of injected code in the context of the user’s browser, with potential for persistence and lateral movement if the user is running privileged processes.
OpenCVE Enrichment
Debian DSA