Impact
The Skia graphics library in Google Chrome contains a flaw in which untrusted input is not properly validated. When a malicious web page triggers the flaw, and the attacker has already gained control of the renderer process, the attacker can read arbitrary data from that process’s memory. The information exposed by this read can include sensitive data, and the vulnerability is identified as CWE‑20.
Affected Systems
All Chrome releases older than version 150.0.7871.46 that include the Skia library are affected. The bug is present in any operating system that runs Chrome on those releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level. An EPSS score of less than 1 % indicates a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw can only be exploited after the renderer process has been compromised; once that condition is satisfied, a crafted web page can trigger the memory read and disclose content.
OpenCVE Enrichment
Debian DLA
Debian DSA