Impact
The integer overflow in the Skia graphics library enables a malicious crafted HTML page to trigger a buffer overrun, resulting in arbitrary code execution within the browser’s sandbox. This can compromise user data or elevate privileges within the sandbox. The flaw is listed as CWE‑190 and CWE‑472.
Affected Systems
Google Chrome versions prior to 147.0.7727.55 are impacted. The issue affects all platforms that the browser supports, including Windows, macOS, and Linux. The Skia library is part of Chromium’s rendering engine used by Chrome.
Risk and Exploitability
The vulnerability carries a high severity score of 8.8 on the CVSS scale, with an EPSS probability of less than 1%. It is not currently listed in the CISA KEV catalog. An attacker can deliver a malicious HTML page through a website or local file, exploiting the flaw when the browser processes the content. No user authentication is required, and the impact is confined to the vulnerable browser instance.
OpenCVE Enrichment
Debian DSA