Impact
An out‑of‑bounds read in the Skia graphics library used by Google Chrome can be triggered by a crafted HTML page. The flaw alone does not grant code execution, but it can be combined with a compromised renderer process to break out of the sandbox and potentially run code on the host. The vulnerability is classified as CWE‑125 and has a CVSS score of 5.8, indicating medium severity.
Affected Systems
Google Chrome browsers prior to version 151.0.7922.72, including all standard desktop builds of Chrome from the stable channel, are affected. The issue resides in the rendering engine that processes web pages in the renderer process.
Risk and Exploitability
The CVSS score of 5.8 reflects a medium‑risk flaw, and the EPSS score of less than 1% shows that exploitation is unlikely. The vulnerability is not in CISA's KEV catalog. Exploitation would require delivering malicious content to a renderer process that is already compromised, after which the out‑of‑bounds read could be leveraged to escape the sandbox and elevate privileges to execute code on the host system.
OpenCVE Enrichment
Debian DLA
Debian DSA