Impact
An integer overflow occurs within Blink, the rendering engine of Google Chrome, when processing certain crafted HTML. The overflow can corrupt the heap, potentially enabling a remote attacker to execute arbitrary code. This flaw is identified as CWE‑472 and is rated critical by Chromium's security team.
Affected Systems
The vulnerability affects Google Chrome versions released before 148.0.7778.96, which are still in use on many consumer and enterprise machines. Any user who opens a malicious web page rendered by an affected Chrome installation is at risk.
Risk and Exploitability
The flaw is not listed in CISA's KEV catalog, and an EPSS score is unavailable, but the Chromium security severity indicates an immediate and high‑risk issue. Attackers can deliver the crafted content to the target via any website or phishing trick; no user interaction beyond visiting a page is required, making exploitation likely unless mitigated. The CVSS score of 8.8 reflects the critical severity of this integer overflow. Applying the latest patch should close the integer overflow and prevent heap corruption.
OpenCVE Enrichment