Description
Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-06
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome contains an out‑of‑bounds write in the Skia graphics library. When executed, the flaw can corrupt memory within the renderer process and, in turn, allow an attacker who controls that process to escape the sandbox. This could enable the attacker to execute code with higher privileges on the host system.

Affected Systems

All installations of Google Chrome that have not yet updated to version 148.0.7778.96 or later are affected. The vulnerability is present in all builds that incorporate a Skia version older than the one fixed in that release.

Risk and Exploitability

The flaw has a CVSS score of 8.3, indicating high severity. Although precise exploit probability data (EPSS) is not available, the vulnerability requires the attacker to compromise the renderer process via a crafted HTML page, implying that the attack surface is tied to malicious web content. The vulnerability is not listed in the CISA KEV catalog, but its potential for sandbox escape places it among the more critical security issues for Chrome users.

Generated by OpenCVE AI on May 7, 2026 at 01:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 148.0.7778.96 or later to eliminate the out‑of‑bounds write
  • If an upgrade cannot be performed immediately, avoid loading untrusted web content that could trigger the renderer—even consider disabling renderer processes or using isolated tabs when browsing known malicious sites
  • Maintain Chrome at the latest available release by enabling automatic updates or frequently checking for security releases

Generated by OpenCVE AI on May 7, 2026 at 01:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title Skia Out-of-Bounds Write Enabling Sandbox Escape in Chrome

Wed, 06 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:15:00 +0000

Type Values Removed Values Added
Title Skia Out-of-Bounds Write Enabling Sandbox Escape in Chrome

Wed, 06 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-07T03:56:51.562Z

Reserved: 2026-05-05T22:59:10.329Z

Link: CVE-2026-7923

cve-icon Vulnrichment

Updated: 2026-05-06T20:45:32.464Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:40.597

Modified: 2026-05-06T23:38:06.913

Link: CVE-2026-7923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:15:17Z

Weaknesses