Impact
The vulnerability is a use‑after‑free flaw in the Skia graphics library used by Google Chrome. An attacker who can compromise a renderer process can use a specially crafted HTML document to execute arbitrary code inside the sandbox, which can lead to full system compromise. The weakness is identified as CWE‑416.
Affected Systems
Google Chrome versions earlier than 151.0.7922.109 are affected. The flaw applies to all platforms that load compromised renderer processes through normal browsing of malicious content.
Risk and Exploitability
The CVE is rated high severity and is not currently listed in the CISA KEV catalog. The EPSS score is not available, so exact exploitation probability is unknown. The exploit requires the attacker to first compromise the renderer process, which is typically achieved with a malicious web page delivered over the network. Once the renderer is subverted, the use‑after‑free can be triggered to execute code within the renderer’s sandbox, potentially breaking out if additional sandbox escapes exist.
OpenCVE Enrichment