Impact
The vulnerability is a heap buffer overflow in the WebRTC implementation of Google Chrome. A remote attacker can trigger memory corruption by delivering a specially crafted HTML document, allowing the attacker to potentially execute arbitrary code on the victim's machine. The issue is categorized as a high severity flaw, aligning with CWEs 122 and 131.
Affected Systems
All installations of Google Chrome older than version 146.0.7680.153 are affected, regardless of operating system. The flaw resides in the browser component and affects users on Windows, macOS, and Linux platforms where the stated Chrome versions run.
Risk and Exploitability
The flaw has a CVSS score of 8.8, indicating high impact, but the EPSS probability is below 1%, suggesting limited exploitation likelihood. It is not listed in the CISA KEV catalog. Attackers would need to load a malicious WebRTC page from a website or email to exploit the buffer; no local privilege escalation or other conditions are required.
OpenCVE Enrichment
Debian DSA