Impact
A heap buffer overflow occurs in the WebML component of Google Chrome on Windows versions prior to 148.0.7778.168, representing a CWE-122 and CWE-787 weakness. The vulnerability allows a remote attacker to supply a specially crafted HTML page that can corrupt the browser's heap memory. Based on the description, it is inferred that heap corruption could lead to arbitrary code execution or other destructive actions, potentially compromising confidentiality, integrity, or availability.
Affected Systems
Google Chrome users on Windows with versions before 148.0.7778.168 are affected by this flaw.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity, but no EPSS value is available, suggesting limited publicly known exploitation. The attack can be launched remotely from a web page, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA