Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
No PoCs from references.
- https://github.com/fdu-sec/NestFuzz
- https://github.com/lysgoup/NestFuzz_test