Impact
The vulnerability is an out‑of‑bounds read in the Skia graphics library used by Google Chrome on macOS. When a renderer process is compromised, the flaw permits reading beyond a legitimate buffer, exposing cross‑origin data normally protected by the same‑origin policy. Classified as CWE‑125, this can lead to a confidentiality breach if code can execute inside that process, retrieving confidential information stored in renderer memory, and the Chromium security team labeled it high severity.
Affected Systems
Google Chrome builds compiled for macOS before version 150.0.7871.47 are affected. Based on the description, it is inferred that the renderer process must be compromised, which could occur if a malicious web page is opened in Chrome.
Risk and Exploitability
The vulnerability requires prior compromise of the renderer process. Based on the description, it is inferred that this is most likely achieved via malicious content delivered to the renderer. The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so the risk is limited in typical environments but would increase if the renderer is already compromised.
OpenCVE Enrichment
Debian DLA
Debian DSA