Impact
This vulnerability is a type confusion flaw in the GFX component of Chrome on Linux and ChromeOS. Compromising the renderer process enables an attacker to load a specially crafted video file that triggers the flaw, allowing the renderer to escape its sandbox and execute code with elevated host privileges. Chromium classified the issue as High severity.
Affected Systems
Google Chrome running on Linux and ChromeOS devices prior to version 148.0.7778.179 are affected. The flaw resides in the GFX subsystem and can be triggered by a malicious video file. No patch version is specified in the data, so users should upgrade to the latest available release.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog; Chromium classified the issue as High severity. Exploitation requires that the attacker first gains control of the renderer process—typically via a malicious webpage or file—and then delivers a crafted video file. While widespread exploitation has not been reported, the potential for arbitrary code execution makes the risk significant.
OpenCVE Enrichment