Impact
Use‑after‑free in the Skia graphics library of Google Chrome occurs when the renderer attempts to use a memory location that has already been deallocated, leading to a sandbox escape when a maliciously crafted HTML page is loaded. The flaw allows a remote attacker who has already compromised the renderer process to elevate privileges within the browser, potentially compromising the confidentiality and integrity of the system. This vulnerability involves a use‑after‑free (CWE‑416) and an improper resource freeing issue (CWE‑825).
Affected Systems
The vulnerability exists in all Google Chrome releases prior to version 150.0.7871.125 on every platform that uses the Skia rendering engine. Users of any affected build are exposed if they load malicious web content that can exploit the renderer.
Risk and Exploitability
With a CVSS score of 8.3 the flaw is high severity, yet the EPSS score of less than 1% indicates exploitation is currently unlikely. It is not listed in the CISA KEV catalog. An attacker would need to first gain control of the renderer—typically by serving a maliciously crafted HTML page or exploiting another renderer issue—and then trigger the use‑after‑free to escape the sandbox. This makes the attack a post‑compromise step rather than a surface‑level vulnerability.
OpenCVE Enrichment
Debian DLA
Debian DSA