Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (Chromium security severity: High)
No PoCs from references.
- https://github.com/fdu-sec/NestFuzz
- https://github.com/lysgoup/NestFuzz_test