Impact
An integer overflow exists in the Skia graphics library used by Google Chrome. When the renderer process is compromised, a specially crafted HTML page can trigger this overflow, allowing an attacker to escape the sandbox that normally isolates renderer processes. The flaw is identified as CWE‑472 and can lead to execution of code outside the intended confined environment.
Affected Systems
Google Chrome browsers with a version older than 150.0.7871.46 are affected. All standard desktop releases that incorporate the Skia library without the recent patch fall within this scope.
Risk and Exploitability
The CVSS score of 8.3 classifies this vulnerability as High. The EPSS score of < 1% indicates a very low likelihood of current exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the likely attack vector involves a malicious web page or plugin that first compromises the renderer process, triggering the overflow; until the update is applied, the potential for sandbox escape remains a significant risk.
OpenCVE Enrichment
Debian DLA
Debian DSA