Impact
A heap buffer overflow occurs in the Media component of Google Chrome, allowing a crafted HTML page to corrupt heap memory. This flaw, classified as CWE‑122, can potentially lead to arbitrary code execution when a user renders the malicious page, posing a severe threat to confidentiality, integrity, and availability of the client system.
Affected Systems
The vulnerability affects all users running Google Chrome versions prior to 145.0.7632.109 on desktop platforms. The affected vendor‑product is Google Chrome, as listed in the CNA data.
Risk and Exploitability
The CVSS base score is 8.8, indicating a high severity. The EPSS probability is under 1 %, and it is not currently listed in the CISA KEV catalog, which suggests exploitation is rare but still plausible. The attack vector requires a user to open a malicious HTML page, so the risk is primarily to users browsing compromised content and is mitigated by applying the security update.
OpenCVE Enrichment
Debian DSA