Impact
The vulnerability is a use‑after‑free in the Skia graphics library used by Google Chrome. The flaw can be triggered by a crafted HTML page that the browser renders. If an attacker can already compromise the renderer process, the memory error may allow the renderer to escape the Chrome sandbox, which can enable arbitrary code execution on the host. The weakness is a memory safety issue, classified as CWE‑416 and CWE‑825.
Affected Systems
Google Chrome versions prior to 149.0.7827.103 on any operating system are affected. The issue resides in the renderer component that processes web pages. Users who run an impacted browser may be exposed if an attacker manages to compromise the renderer process through a malicious web page.
Risk and Exploitability
CVSS score is 8.3, indicating high severity. The EPSS score is less than 1%, suggesting low probability of exploitation in the wild. The vulnerability is listed under Chrome's Chromium security severity as High, but it requires a remote attacker to have already compromised the renderer process. The attack typically involves presentation of a crafted web page that the renderer loads. Because the necessary conditions are restrictive, exploitation is expected to be difficult, but once achieved, the sandbox escape could compromise the host system. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DSA