Impact
An out‑of‑bounds read was discovered in the Media component of Google Chrome before version 147.0.7727.101. The flaw permits a remote adversary to trigger a crafted HTML page that, when a user performs specific UI gestures, can lead to arbitrary code execution. The vulnerability falls under CWE‑125 and is classified as high severity by Chromium security.
Affected Systems
The issue affects any installation of Google Chrome running a version earlier than 147.0.7727.101. The vulnerability is limited to the Chrome browser; no other Google or third‑party products are listed as affected.
Risk and Exploitability
Because exploitation requires a user to visit a maliciously constructed web page and perform certain gestures, the attack vector relies on social engineering to get the user to interact with the page. The CVSS score is 7.5, and the EPSS score is <1%, indicating a low probability of exploitation, yet the problem remains high risk due to remote code execution potential. The vulnerability is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DSA