Impact
An integer overflow in Chrome's Blink rendering engine occurs when processing crafted HTML, leading to heap corruption that could allow a remote attacker to execute arbitrary code. This flaw combines the weaknesses of CWE‑472 (Heap Corruption) and CWE‑190 (Integer Overflow), and has been rated critical by Chromium security.
Affected Systems
The vulnerability affects Google Chrome versions released before 148.0.7778.96, which are still in use on many consumer and enterprise machines. Any user who opens a malicious web page rendered by an affected Chrome installation is at risk.
Risk and Exploitability
The flaw is not listed in CISA's KEV catalog, and the EPSS score is less than 1%, indicating a low current exploit probability; however, the Chromium security severity is critical and the CVSS score of 8.8 reflects the high risk of this integer overflow. Attackers can deliver malicious content via a simple web page or phishing link; no user interaction beyond visiting a page is required, making exploitation likely unless mitigated. Applying the latest Chrome patch should eliminate the integer overflow and stop heap corruption.
OpenCVE Enrichment
Debian DSA