Impact
A heap buffer overflow occurs in the WebAudio component of Google Chrome prior to version 147.0.7727.55. When a malicious HTML page is loaded, the overflow allows a remote attacker to read data from process memory, potentially exposing confidential information. The weakness is a classic buffer overflow that bypasses normal memory safety checks.
Affected Systems
All installations of Google Chrome up to the 147.0.7727.55 release are affected. This includes Windows, macOS, and Linux platforms that run the vulnerable browser version. Users who open a crafted web page in these browsers may be impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: a threat actor serves a malicious web page that the victim visits, triggering the buffer overflow without requiring prior local compromise.
OpenCVE Enrichment
Debian DSA