Impact
A heap buffer overflow occurs in Chrome's Codecs module, allowing a remote attacker to craft a video file that, when processed, triggers an out‑of‑bounds write and executes arbitrary code inside the browser’s sandbox. The flaw can be leveraged to compromise the integrity of the browser environment and, depending on other software interactions, could lead to further system compromise.
Affected Systems
The vulnerability affects Google Chrome versions earlier than 148.0.7778.168 on all supported platforms. Users running these versions are susceptible unless the browser is updated.
Risk and Exploitability
No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog; however, the CVSS score is 8.8, indicating high severity. The attack vector likely requires a user to open or process a specially crafted video file, potentially through a web page or local media player. Because the exploit runs inside the Chrome sandbox, the attacker gains code execution within that confined environment, which could be leveraged to escape the sandbox if additional weaknesses exist. Given the absence of public exploit code but the high severity rating, administrators should treat this as a high‑risk issue that warrants immediate attention.
OpenCVE Enrichment
Debian DSA