Sceawere
Vulnerability Detail
CVE-2026-95318UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Chrome Video Buffer Overflow
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 7h ago
- Vendor
- Product
- Chrome
- Attack Type
- Buffer overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-09-29T18:17:24.060Z",
"pubdate": "2026-09-29T18:17:24.060Z",
"executiveSummary": "A high-severity buffer overflow vulnerability exists within the Video component of Google Chrome prior to version 154.0.8037.57.\nThis memory corruption flaw allows a remote, unauthenticated attacker to execute arbitrary code outside the browser's security sandbox environment.\nThe vulnerability is triggered when a user navigates to a maliciously crafted HTML page designed to exploit the flaw in video processing logic.\nSuccessful exploitation compromises the integrity, confidentiality, and availability of the host system, as the attacker can bypass sandbox restrictions to execute code with the privileges of the application process.\nGiven that this vulnerability can be leveraged via standard web browsing, the risk to end-users is substantial, necessitating prompt patching to the latest stable release.",
"technicalDetails": "The vulnerability originates from an out-of-bounds memory management error located within the Video processing subsystem of the Chromium engine. This occurs when the browser fails to properly validate the size or structure of data during video stream rendering or container parsing.\nThe root cause is identified as a buffer overflow, where an attacker-supplied input exceeds the allocated memory boundaries of the heap or stack during the processing of a crafted media element. Because the Video component manages complex codecs and data structures, insufficient bounds checking permits the overwriting of adjacent memory blocks.\nThe exploitation flow typically begins when a target user navigates to an attacker-controlled HTML page. This page contains an embedded video object configured with malformed parameters or headers that specifically target the identified flaw in the media processing logic.\nUpon loading the crafted media, the browser's video parser enters an inconsistent state, leading to memory corruption. By carefully structuring the payload, an attacker can overwrite critical function pointers or return addresses stored in memory. This redirection of the instruction pointer facilitates control over the program execution flow.\nA significant attribute of this vulnerability is its ability to bypass the Chromium sandbox. By triggering the vulnerability, the attacker can execute arbitrary code that transitions from the restricted media parsing process to the host operating system level, effectively escaping the browser's containment mechanisms. This post-exploitation behavior grants the attacker persistent or immediate control depending on the specific payload utilized during the heap manipulation phase.\nThe vulnerability affects all versions of Google Chrome preceding 154.0.8037.57. Exploitation does not require prior authentication or elevated privileges, as the browser processes untrusted web content by design. The attack vector is purely network-based, relying on the user's interaction with a malicious URI."
}