Impact
An out‑of‑bounds read bug in Skia, the graphics library used by Google Chrome, permits a remote attacker to read portions of memory belonging to the sandboxed renderer when a crafted media file is processed. This flaw can expose confidential data or aid in further sandbox escape, compromising confidentiality and potentially integrity. The vulnerability is a memory disclosure caused by an out‑of‑bounds read (CWE‑125).
Affected Systems
Google Chrome 152.0.7977.64 and earlier desktop versions are affected. The issue was fixed in Chrome 152.0.7977.65, so any installation of an earlier version should be updated to the patched release.
Risk and Exploitability
The flaw is exploitable via a malicious media file, suggesting a drive‑by or email‑based attack vector. Exploitation would occur within the sandbox, making it useful for data exfiltration or as a stepping stone to other attacks. The CVSS score of 8.1 indicates a high severity level. EPSS score is less than 1%, suggesting a low probability of active exploitation, and the vulnerability is not listed in CISA's KEV catalog. Because the attack surface includes any user who opens a crafted file, administrators should treat this as an elevated risk until the patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA