Impact
Improper state validation in the Skia graphics library used by Google Chrome, classified as CWE-754 and also exhibiting an out‑of‑bounds read (CWE-125), allows a remote attacker who has already compromised the renderer process to read memory outside the expected sandbox boundaries. This flaw can lead to disclosure of information stored in the renderer, as the attacker can access memory that should be protected by the sandbox.
Affected Systems
Google Chrome desktop releases before version 153.0.8010.47 on all platforms supported by Skia are impacted. No other Chrome products or platforms are listed.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. Because the EPSS score is below 1%, the likelihood of exploitation in the wild is very low. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the attacker to first compromise the renderer process, typically via a malicious web page or other user‑initiated action. Once the renderer is compromised, the attacker may read memory beyond the sandbox. The likely attack vector is inferred to be a crafted web page that triggers the state validation bug.
OpenCVE Enrichment
Debian DLA
Debian DSA