Impact
This vulnerability is an out‑of‑bounds write in the Skia graphics library used by Google Chrome. A remote attacker who has succeeded in compromising the renderer process can craft an HTML page that triggers the memory corruption. If the exploit succeeds, the attacker may break out of the renderer sandbox and gain the privileges of the browser process, leading to arbitrary code execution on the vulnerable host.
Affected Systems
Google Chrome web browsers that are older than version 151.0.7922.109 are affected, as the issue was fixed in that release. Users executing earlier stable channel builds are at risk.
Risk and Exploitability
The CVE is classified as a Chromium security severity of High. No EPSS score is published and the vulnerability is not listed in the CISA KEV catalog, which limits publicly available exploit data. The likely attack path involves an attacker hosting a malicious web page that a user visits, exploiting the renderer process after it has already been compromised. Due to the absence of public exploit code and the limited exploitation window, the overall risk remains moderate but still warrants immediate action.
OpenCVE Enrichment