Impact
Uninitialized Skia resources in Google Chrome versions prior to 152.0.7977.65 allow a remote attacker who has already compromised the renderer process to potentially read data from other browser origins through a specially crafted HTML page. The weakness consists in an inadequate validation of a resource used by the Skia graphics library, which can lead to a confidentiality loss, as defined by the associated CWE-908.
Affected Systems
The vulnerability affects Google Chrome on all platforms for versions earlier than 152.0.7977.65. The issue was identified in the renderer process that draws web content using the Skia library.
Risk and Exploitability
The CVE is not listed in the CISA KEV catalog and the EPSS score is < 1%, indicating a very low exploitation probability. Exploitation requires that the attacker already compromises the renderer process, so the attack vector is a chained attack. The Chromium advisory rates the severity as Medium, as reflected by a CVSS score of 3.1, indicating moderate risk for environments that expose Chrome to untrusted content.
OpenCVE Enrichment
Debian DLA
Debian DSA