Impact
An integer overflow occurs in the Skia graphics library used by Google Chrome. The flaw allows an attacker who has already compromised the renderer process to execute arbitrary code within the sandbox through a specially crafted HTML page. This flaw corresponds to the CWE‑190 Integer Overflow or Wraparound weakness. This vulnerability is classified as high severity.
Affected Systems
Google Chrome browsers with versions earlier than 148.0.7778.216 are affected. Only the Chrome product is impacted.
Risk and Exploitability
The vulnerability can be triggered by serving a malicious page that exploits the Skia overflow. While the attack requires prior compromise of the renderer process, once reached it provides remote code execution inside the sandboxed environment. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploits at this time. The CVSS score of 7.5 indicates a high severity, suggesting that exploitation would likely be attempted once the flaw is discovered.
OpenCVE Enrichment