Impact
A use‑after‑free vulnerability in the Skia graphics library of Google Chrome allows an attacker, after compromising the renderer process, to potentially escape the process sandbox by loading a crafted HTML page. The flaw can lead to arbitrary code execution if the attacker controls the renderer. The primary weakness is a memory safety issue, identified as CWE‑416.
Affected Systems
Google Chrome versions prior to 149.0.7827.103 are affected. The vulnerability exists in the renderer component that renders web pages, and any user who visits a malicious page while the browser is running may expose the system to risk.
Risk and Exploitability
The advisory lists the Chromium security severity as High, the CVSS score is 8.3, and the EPSS score is not available. The vulnerability requires an attacker to already have control over the renderer process, which is a significant prerequisite. While an explicit exploitation path is not detailed, the potential for sandbox escape means that successful exploitation could compromise the host system.
OpenCVE Enrichment