Impact
An integer overflow occurs in the Skia graphics library used by Google Chrome, allowing a remote attacker to use a specially crafted HTML page to read data from other origins. This flaw results in a confidentiality breach where sensitive data can be exposed to the attacker. The weakness is an instance of integer overflow (CWE‑190).
Affected Systems
Google Chrome versions earlier than 154.0.8037.97 across all platforms are affected. The vulnerability was discovered in the Skia library used by the browser.
Risk and Exploitability
The bug is rated high severity with no EPSS score available, and it is not currently listed in the CISA KEV catalog. The exploit requires the victim to open a carefully crafted web page, after which the overflow can be triggered in memory. Because the attack occurs in the rendering engine, a remote attacker can obtain cross-origin data from any site the victim visits while the browser is running. No additional prerequisites were identified beyond user interaction with the malicious page.
OpenCVE Enrichment