Impact
A heap buffer overflow in Chrome's CSS engine allows a remote attacker to corrupt memory by loading a specially crafted HTML page. The vulnerability can lead to arbitrary code execution, compromising the confidentiality, integrity, and availability of the user’s system while the browser is running.
Affected Systems
The flaw affects all versions of Google Chrome prior to 146.0.7680.153 on Windows, macOS, and Linux. Systems that have not applied the latest Chrome update are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation can be achieved remotely by delivering the crafted web content to a user visiting a malicious site, potentially allowing the attacker to gain control of the browser process and, with further exploitation steps, the underlying operating system.
OpenCVE Enrichment
Debian DSA