Impact
A stack buffer overflow occurs within Skia, the graphics library used by Google Chrome, when it processes a specially crafted HTML page. The flaw, identified as CWE‑120 and CWE‑121, allows a remote attacker to corrupt the browser’s stack. This corruption can lead to arbitrary code execution in the context of the user's browser.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 are affected. Users who have not yet updated to a recent release must address the issue immediately.
Risk and Exploitability
The CVSS score of 8.8 points to a high‑severity vulnerability. The EPSS score is less than 1%, indicating a low but nonzero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would likely need to trick a user into visiting a malicious web page or clicking a link that loads the vulnerable content, at which point stack corruption can lead to remote code execution. Because the flaw is an unmitigated stack overflow in a core rendering component, the potential impact is high if exploited, though the exploitation probability remains low as of this assessment.
OpenCVE Enrichment
Debian DSA