Impact
The vulnerability is an out-of-bounds read within the AdFilter component of Google Chrome. This bounds-check omission (CWE-125) permits a remote actor to supply a specifically crafted HTML page that causes the browser to read beyond a valid buffer, potentially enabling execution of arbitrary code within Chrome’s sandboxed environment. Although the sandbox limits what can be done directly, a successful escape from the sandbox could compromise the host system.
Affected Systems
All users of Google Chrome versions earlier than 148.0.7778.96 are affected. The issue appears across all operating systems supported by Chrome, as the AdFilter code is platform-agnostic and no partial patches exist for earlier releases.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, yet the capacity for remote code execution inside a sandboxed environment represents serious risk. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is over the network: an attacker can host a malicious web page that the victim visits. Because the flaw requires only a crafted HTML page, it is relatively straightforward for adversaries to exploit in the wild, underscoring the urgency of remediation.
OpenCVE Enrichment
Debian DSA