Impact
The flaw originates from insufficient validation of untrusted input in Skia, the graphics library used by Google Chrome (CWE-20). When a malicious HTML page is parsed by a renderer process that the attacker has already compromised, Skia may process the input incorrectly, allowing the attacker to escape the renderer's sandbox and execute code with the privileges of the browser process.
Affected Systems
All users running Google Chrome versions earlier than 150.0.7871.47 are affected. The vulnerability resides in the rendering component and is only exploitable after the attacker has compromised the renderer process.
Risk and Exploitability
The CVSS score is 9.6 and the EPSS score is <1%. It is not listed in the CISA KEV catalog. Exploitation requires that the attacker first gain control of the renderer process; based on the advisory, it is inferred that a publicly available exploit has not yet been realized.
OpenCVE Enrichment
Debian DLA
Debian DSA