Impact
A flaw in Chrome’s WebAudio implementation permits an out‑of‑bounds read and write, allowing a remote attacker to corrupt the page’s heap. When the webpage is rendered, the corrupted heap can lead to arbitrary code execution, compromising the confidentiality, integrity, and availability of the user’s system. The weakness corresponds to CWE‑125 and CWE‑787.
Affected Systems
Google Chrome browsers prior to version 146.0.7680.153 are affected, regardless of operating system; the issue applies to Windows, macOS, and Linux deployments of the browser.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. The EPSS score of less than 1% suggests a low likelihood of current exploitation, and it is not listed in CISA’s KEV catalog. The flaw can be triggered from a malicious webpage, implying a remote web‑based attack vector where an attacker hosts a crafted HTML page to exploit the WebAudio bug and achieve code execution.
OpenCVE Enrichment
Debian DSA