Impact
An integer overflow occurs in the media parsing code of Google Chrome's video handling component. The overflow can corrupt heap structures when processing a maliciously crafted video file, potentially compromising the browser's integrity and allowing an attacker to execute code or crash the application. The issue is classified under CWE-190 and CWE-472, reflecting an integer calculation error that results in a buffer vulnerability.
Affected Systems
The flaw is present in Google Chrome versions older than 147.0.7727.55 across all supported operating systems, including Windows, macOS, and Linux distributions. Attackers can target users running these versions by presenting a malicious video file.
Risk and Exploitability
With a CVSS score of 8.8, this vulnerability is considered high severity. The EPSS score of less than 1% and its absence from CISA's KEV catalog suggest that exploitation is currently uncommon, but the high potential impact warrants caution. The most likely attack vector involves a user opening a compromised video file while browsing or within a web page, giving the attacker a path to leverage the overflow.
OpenCVE Enrichment
Debian DSA