Impact
An integer overflow bug in the Skia graphics library used by Google Chrome enables a remote attacker to potentially exploit heap corruption by loading a specially crafted HTML page. This vulnerability is defined as a classic buffer‑overrun condition (CWE‑122), which could lead to a denial of service if successfully triggered. The CVE does not claim or imply arbitrary code execution; it only indicates the possibility of heap corruption.
Affected Systems
The issue affects Google Chrome versions earlier than 149.0.7827.53. Users running any affected build are vulnerable, and the flaw was remedied in the 149.0.7827.53 stable release.
Risk and Exploitability
No CVSS or EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation is known. Chromium assigns a medium security severity. The likely attack vector is a malicious web page that a user visits; exploitation could result in heap corruption and a potential denial of service but is not documented to lead to code execution.
OpenCVE Enrichment