Description
Out of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in the Skia graphics library used by Google Chrome on macOS. When a renderer process is compromised, the flaw permits reading beyond a legitimate buffer, exposing cross‑origin data normally protected by the same‑origin policy. Classified as CWE‑125, this can lead to a confidentiality breach if code can execute inside that process, retrieving confidential information stored in renderer memory, and the Chromium security team labeled it high severity.

Affected Systems

Google Chrome builds compiled for macOS before version 150.0.7871.47 are affected. Based on the description, it is inferred that the renderer process must be compromised, which could occur if a malicious web page is opened in Chrome.

Risk and Exploitability

The vulnerability requires prior compromise of the renderer process. Based on the description, it is inferred that this is most likely achieved via malicious content delivered to the renderer. The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so the risk is limited in typical environments but would increase if the renderer is already compromised.

Generated by OpenCVE AI on July 31, 2026 at 16:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on macOS to version 150.0.7871.47 or newer to apply the Skia patch that eliminates the out‑of‑bounds read.
  • Run Chrome with the system's security features such as System Integrity Protection and Gatekeeper enabled to restrict renderer privileges and reduce the impact of memory corruption.
  • Deploy endpoint monitoring or intrusion‑detection tools that log abnormal renderer crashes or memory‑access violations, and investigate any such events promptly to detect attempted exploitation.

Generated by OpenCVE AI on July 31, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Cross-Origin Data Leak in Chrome on macOS

Mon, 27 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Cross-Origin Data Leak in Chrome on macOS

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Skia Out‑of‑Bounds Read Leading to Cross‑Origin Data Leak in Chrome on macOS

Fri, 17 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Skia Out‑of‑Bounds Read Leading to Cross‑Origin Data Leak in Chrome on macOS

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Cross-Origin Data Leak on macOS Chrome

Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Cross-Origin Data Leak on macOS Chrome

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Skia Enables Remote Data Leak on macOS

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Skia Enables Remote Data Leak on macOS

Sat, 11 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Cross-Origin Data Leak on macOS Chrome

Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Cross-Origin Data Leak on macOS Chrome

Thu, 09 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Skia Out-of-Bounds Read in Chrome for macOS Enables Remote Data Leak

Wed, 08 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Skia Out-of-Bounds Read in Chrome for macOS Enables Remote Data Leak

Tue, 07 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Remote Data Leak on macOS Chrome

Mon, 06 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Remote Data Leak on macOS Chrome

Mon, 06 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Cross‑Origin Data Leak in Chrome on macOS

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enables Cross‑Origin Data Leak in Chrome on macOS

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Skia Enables Cross‑Origin Data Leak on macOS Chrome

Sat, 04 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Skia Enables Cross‑Origin Data Leak on macOS Chrome

Sat, 04 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Causing Remote Data Leak on macOS

Thu, 02 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Causing Remote Data Leak on macOS

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enabling Cross-Origin Data Leak in Chrome for macOS

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Skia Enabling Cross-Origin Data Leak in Chrome for macOS

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Skia Enables Remote Data Leak on macOS

Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Skia Enables Remote Data Leak on macOS

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:09:18.053Z

Reserved: 2026-06-29T23:03:25.707Z

Link: CVE-2026-13820

cve-icon Vulnrichment

Updated: 2026-07-01T15:08:03.587Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:30:17Z

Weaknesses