Impact
Google Chrome versions prior to 146.0.7680.71 contain an out‑of‑bounds memory access flaw in WebML. A crafted HTML page can trigger heap corruption that may allow a remote attacker to execute arbitrary code. The vulnerability is classified as a high‑severity memory corruption bug, exposed through improper bounds checking (CWE‑125 and CWE‑787).
Affected Systems
The affected product is Google Chrome on all supported operating systems, including Windows, macOS, and Linux distributions, for any version earlier than 146.0.7680.71. All users running these outdated Chrome builds are susceptible through standard web browsing.
Risk and Exploitability
The CVSS score of 8.8 indicates a high risk of exploitation. Although the EPSS score is below 1%, the bug remains a serious threat given the potential impact. The vulnerability is not listed in CISA’s KEV catalog, but attackers could target browsers via malicious web content, exploiting the heap corruption to hijack execution. The likelihood of exploitation is low but notable enough to warrant immediate mitigation.
OpenCVE Enrichment
Debian DSA