Impact
A buffer overread occurs in the WebCodecs component of Google Chrome, allowing a remote attacker to read arbitrary memory data when a specially crafted video file is processed. The flaw is a classic out‑of‑bounds read (CWE‑125) and can expose sensitive information contained in the victim’s process address space. No privileged escalation or code execution is achievable solely through this vulnerability, but the data exposed may enable additional attacks or compromise user privacy.
Affected Systems
Google Chrome versions earlier than 148.0.7778.96 are affected. The vulnerability exists in the WebCodecs implementation shipped with those releases. Systems running the specified or older versions should be considered at risk until an update is applied.
Risk and Exploitability
The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate exploitation risk. A remote attacker can trigger the overread by hosting a malicious video file or sending it to a victim via a vulnerable web page. The exploit requires no special conditions beyond the ability to deliver the crafted file to a Chrome instance running the affected version. The CVSS score of 4.3 reflects a Medium severity, suggesting that the risk is not trivial but warrants timely patching to prevent data leakage.
OpenCVE Enrichment
Debian DSA