Impact
An integer overflow occurs in the media component of Google Chrome versions older than 147.0.7727.55. The flaw allows a crafted video file to corrupt heap memory during decoding, creating a potential vulnerability for arbitrary code execution. The defect is classified under CWE-190 (Integer Overflow) and CWE-472 (Incorrect Index).
Affected Systems
The vulnerability affects Google Chrome browsers on Windows, macOS, and Linux platforms. Users running any Chrome version prior to 147.0.7727.55 are susceptible, regardless of operating system or installation location.
Risk and Exploitability
The flaw carries a high severity rating of 8.8 and an exploit likelihood estimated below 1%, indicating that active exploitation is unlikely and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would need a victim to open a maliciously crafted video file or link that automatically plays the media, after which the heap corruption could be leveraged to compromise the browser or underlying system.
OpenCVE Enrichment
Debian DSA