Impact
An integer overflow in Skia, the graphics engine used by Google Chrome, can be triggered by a crafted HTML page. When the overflow occurs during page rendering, it may allow a remote attacker to escape Chrome’s sandbox and execute code with the privileges of the browser process. The flaw is categorized as CWE‑472, indicating a failure to validate integer boundaries properly.
Affected Systems
Google Chrome versions prior to 150.0.7871.46 are vulnerable. Users running Chrome 150.0.7871.45 or any older release may be exposed; the update to 150.0.7871.46 replaces the affected Skia code and removes the vulnerability.
Risk and Exploitability
The CVSS score of 9.6 marks the issue as critical, while the EPSS score of < 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker delivering a malicious HTML page to a user’s browser, which could trigger the overflow and grant sandbox escape.
OpenCVE Enrichment
Debian DLA
Debian DSA