Impact
Google Chrome contains an out‑of‑bounds write in the Skia graphics library. When executed, the flaw can corrupt memory within the renderer process and, in turn, allow an attacker who controls that process to escape the sandbox. This could enable the attacker to execute code with higher privileges on the host system.
Affected Systems
All installations of Google Chrome that have not yet updated to version 148.0.7778.96 or later are affected. The vulnerability is present in all builds that incorporate a Skia version older than the one fixed in that release.
Risk and Exploitability
The flaw has a CVSS score of 8.3, indicating high severity. Although precise exploit probability data (EPSS) is not available, the vulnerability requires the attacker to compromise the renderer process via a crafted HTML page, implying that the attack surface is tied to malicious web content. The vulnerability is not listed in the CISA KEV catalog, but its potential for sandbox escape places it among the more critical security issues for Chrome users.
OpenCVE Enrichment
Debian DSA