Impact
An integer overflow in the Media component of Google Chrome before 147.0.7727.55 can be triggered by a specially crafted video file. The overflow corrupts heap memory, and while the vulnerability is classified as low, it could potentially allow a remote attacker to execute arbitrary code if successfully exploited.
Affected Systems
Users running Google Chrome versions earlier than 147.0.7727.55 are affected. The flaw exists only in the media processing subsystem and does not apply to other parts of the browser.
Risk and Exploitability
The exploitation likelihood is not quantified in EPSS and the vulnerability is not listed in CISA’s KEV catalog. The low CVSS score indicates limited ease of exploitation. The attack vector is inferred to be remote delivery of a malicious video file that is then processed by the victim’s browser, requiring crafted input and possibly additional conditions to succeed.
OpenCVE Enrichment