Impact
The Skia graphics library in Google Chrome contains an insufficient validation flaw that, when triggered by a specially crafted HTML page, permits a remote attacker who has already compromised the renderer process to read arbitrary data from that process’s memory. The attack results in the disclosure of potentially sensitive information such as passwords or cryptographic material, a classic information‑disclosure vector that falls under CWE‑20 and is assigned a CVSS score of 5.3.
Affected Systems
All Chrome releases older than version 150.0.7871.46 that include the Skia library are affected. Because Chrome’s renderer process is common across all supported operating systems, the vulnerability applies to every platform that runs these releases.
Risk and Exploitability
The flaw can be leveraged only after an attacker has succeeded in compromising the renderer process. Once that prerequisite is met, the attacker can serve a malicious web page that triggers the vulnerability, leading to a modest confidentiality impact but no integrity or availability damage. The EPSS score of less than 1 % indicates a low likelihood of widespread exploitation, and the vulnerability is not catalogued in the CISA KEV list. The CVSS rating of 5.3 reflects a moderate risk level within the normal security landscape.
OpenCVE Enrichment
Debian DLA
Debian DSA