Impact
The vulnerability is an out-of-bounds read in the Skia graphics library used by Google Chrome on macOS. When a renderer process is compromised, the flaw permits reading beyond a legitimate buffer, exposing cross-origin data normally protected by the same-origin policy. Classified as CWE‑125, this can lead to a confidentiality breach if an attacker can execute code in that process, retrieving confidential information stored in renderer memory, and the Chromium security team labeled it high severity.
Affected Systems
Google Chrome builds compiled for macOS before version 150.0.7871.47 are affected. Based on the description, it is inferred that any installation that allows a renderer process to run with elevated privileges could be vulnerable if an attacker can compromise that process, such as through a malicious web page or a local privilege escalation that targets the renderer.
Risk and Exploitability
The opportunity for exploitation requires prior compromise of the renderer process, which typically requires a separate vulnerability or a local privilege escalation. The CVSS score of 6.5 indicates medium severity, whereas the EPSS score of less than 1% shows a low probability of exploitation per year. The vulnerability is not listed in the CISA KEV catalog, so the risk is limited in typical environments, but it rises significantly if renderer code is already compromised or if an attacker can elevate privileges on the host.
OpenCVE Enrichment
Debian DLA
Debian DSA