Impact
An information‑leak vulnerability exists in the Skia graphics library used by Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to read sensitive data from memory via a crafted HTML page, potentially exposing confidential material. The weakness is categorized as information disclosure (CWE-200).
Affected Systems
Google Chrome browsers that run the vulnerable Skia library, specifically those versions earlier than 152.0.7977.65. The issue was reported in the Chromium security tracker and is documented as impacting all installations using the default rendering path.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, reflecting low severity in Chromium’s metrics, and no high‑severity exploitation score is available. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog. Attackers would first need to compromise the renderer process, which likely requires a prior compromise of the browser or the host system. Once in place, they could execute crafted HTML to extract data, though this requires a sophisticated threat actor and is not trivially achievable from a remote network alone.
OpenCVE Enrichment
Debian DLA
Debian DSA