Impact
An integer overflow occurs in the WebML component of Google Chrome, allowing a remote attacker to craft an HTML page that triggers heap corruption. This flaw aligns with the integer overflow weakness (CWE‑190) and an overflow during memory allocation (CWE‑472). The resulting heap corruption could lead to arbitrary code execution or a privileged escalation on the host system.
Affected Systems
The vulnerability affects Google Chrome versions prior to 147.0.7727.55 on all supported operating systems—macOS, Linux, and Windows—since Chrome includes the WebML engine across platforms.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score is below 1 %, suggesting limited publicly known exploitation. The flaw is not listed in the CISA KEV catalog. Attackers require only a malicious web page to be opened in Chrome, which makes the attack vector likely remote via browsers. Without official proof of exploitation, the risk is theoretical but high enough to warrant immediate patching.
OpenCVE Enrichment
Debian DSA