Debian released updates to gst-plugins-base1.0 to fix an integer overflow in GStreamer's RIFF parser. A malformed media file may trigger denial of service or potentially enable arbitrary code execution when opened.
NVD KEV
Known exploited · CISA KEV
CVSS 8.8 HIGH: out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 33% (97th percentile). Microsoft patch: Release Notes.
CISA federal remediation date Mar 27
NVD KEV
Known exploited · CISA KEV
CVSS 8.8 HIGH: inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 23% (96th percentile). Microsoft patch: Release Notes.
CISA federal remediation date Mar 27