Impact
An integer overflow in Skia, the graphics engine used by Google Chrome, can be triggered by a crafted HTML page. When the overflow occurs during page rendering, it may allow a remote attacker to escape Chrome’s sandbox and execute code with the privileges of the browser process. The flaw is categorized as CWE‑472, indicating a failure to validate integer boundaries properly.
Affected Systems
Google Chrome versions earlier than 150.0.7871.46 are vulnerable. Users running Chrome 150.0.7871.45 or any older release may be exposed; the update to 150.0.7871.46 replaces the affected Skia code and removes the vulnerability.
Risk and Exploitability
The CVSS score of 9.6 marks the issue as critical. The EPSS score of < 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker delivering a malicious HTML page to a user’s browser, which could trigger the overflow and grant sandbox escape.
OpenCVE Enrichment
Debian DLA
Debian DSA