Impact
An out‑of‑bounds read in the Skia graphics library within Google Chrome can be triggered by a crafted HTML page, allowing a remote attacker to read and leak cross‑origin data from memory. The vulnerability is a buffer over‑read (CWE‑125) that compromises data confidentiality. There is no impact on integrity or availability beyond the information disclosure.
Affected Systems
Google Chrome browsers running any operating system, specifically versions prior to 149.0.7827.53. The flaw exists in all standard releases that include the affected Skia code base.
Risk and Exploitability
The flaw carries a high severity rating and is not currently listed in CISA’s KEV catalog, nor is an EPSS value available. Attackers could exploit it by hosting or convincing a victim to load a malicious web page that triggers the vulnerable Skia rendering path. No privileged access or elevated permissions are required; a typical user visiting an attacker‑controlled site would be sufficient.
OpenCVE Enrichment