Description
Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: High‑severity out‑of‑bounds read leading to memory disclosure
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds read bug in Skia, the graphics library used by Google Chrome, permits a remote attacker to read portions of memory belonging to the sandboxed renderer when a crafted media file is processed. This flaw can expose confidential data or aid in further sandbox escape, compromising confidentiality and potentially integrity. The vulnerability is a memory disclosure caused by an out‑of‑bounds read (CWE‑125).

Affected Systems

Google Chrome 152.0.7977.64 and earlier desktop versions are affected. The issue was fixed in Chrome 152.0.7977.65, so any installation of an earlier version should be updated to the patched release.

Risk and Exploitability

The flaw is exploitable via a malicious media file, suggesting a drive‑by or email‑based attack vector. Exploitation would occur within the sandbox, making it useful for data exfiltration or as a stepping stone to other attacks. The CVSS score of 8.1 indicates a high severity level. EPSS score is less than 1%, suggesting a low probability of active exploitation, and the vulnerability is not listed in CISA's KEV catalog. Because the attack surface includes any user who opens a crafted file, administrators should treat this as an elevated risk until the patch is applied.

Generated by OpenCVE AI on August 28, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer on all affected systems.
  • Disable or restrict Skia‑rendered media handling via group policy or security settings to reduce the surface for crafted media files if an update cannot be applied immediately.
  • Keep monitoring Google Chrome release notes and security advisories for additional mitigations or related vulnerabilities.

Generated by OpenCVE AI on August 28, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Sat, 05 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 31 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Skia Out-of-Bounds Read Allowing Memory Disclosure via Crafted Media File

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}


Wed, 26 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Skia Out-of-Bounds Read Allowing Memory Disclosure via Crafted Media File

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (Chromium security severity: Medium)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:57:29.207Z

Reserved: 2026-08-25T06:07:35.679Z

Link: CVE-2026-79020

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:57.857

Modified: 2026-08-31T13:39:29.637

Link: CVE-2026-79020

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-25T20:10:29Z

Links: CVE-2026-79020 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:00:14Z

Weaknesses