Impact
A heap buffer overflow exists in the WebAudio component of Google Chrome versions prior to 146.0.7680.165. The overflow is triggered when an attacker serves a specially crafted HTML page that causes an out‑of‑bounds write into heap memory. This memory corruption can potentially be leveraged to execute arbitrary code or crash the browser, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Google Chrome on all desktop platforms – Windows, macOS, and Linux – in releases older than 146.0.7680.165. Anyone running these versions of Chrome is potentially exposed when rendering malicious web content.
Risk and Exploitability
The CVSS score of 8.8 categorizes the issue as high, and the low EPSS (<1%) indicates current exploit activity is unlikely. The exploit requires a victim to load a malicious page, which can be delivered via phishing, compromised sites, or social engineering. Once triggered, the out‑of‑bounds write can lead to arbitrary code execution, so the risk is significant for privileged users or when the browser runs with elevated rights. The CVE is not yet in the CISA KEV catalog, but administrators should still treat it as a high‑severity concern.
OpenCVE Enrichment
Debian DSA