Impact
This vulnerability is an out‑of‑bounds read in the Skia graphics subsystem used by Google Chrome. A crafted file can trigger the read and expose data from Chrome’s process memory, enabling an attacker to retrieve potentially sensitive information. The Chromium team rates the severity as Medium.
Affected Systems
Google Chrome versions prior to 147.0.7727.101 on all supported operating systems are affected. The flaw originates in the Skia library, so any installation of Chrome that uses that library is at risk, regardless of the user’s platform.
Risk and Exploitability
The estimated probability of exploitation is low and the vulnerability has not been listed in the CISA catalog of known exploited vulnerabilities. However, the vulnerability carries a medium severity rating of 6.5 on the Common Vulnerability Scoring System, indicating a notable risk. An attacker can exploit this remotely by delivering a crafted file that a user opens; Chrome will then read memory outside the bounds of the image buffer. The exploit requires only that the user view the file and does not depend on elevated privileges, making it accessible through social engineering or phishing. Once the out‑of‑bounds read occurs, an attacker can capture arbitrary data such as cookies or cached credentials stored in memory.
OpenCVE Enrichment
Debian DSA