Impact
The vulnerability is a use‑after‑free in the Skia graphics library used by Google Chrome. When a renderer process is compromised, a crafted HTML page can trigger the flaw, potentially allowing the attacker to escape the browser sandbox and execute arbitrary code on the host. The flaw is rated critical by Chromium security, indicating a high likelihood of exploitation if the attacker controls the renderer. The issue is associated with both CWE-416 and CWE-825.
Affected Systems
Affected systems are all installations of Google Chrome running any version earlier than 148.0.7778.216. The issue resides in the renderer component that supports rendering images and graphics via Skia; thus any platform that runs Chrome with that renderer is vulnerable. The weakness falls under both CWE‑416 and CWE‑825.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. EPSS score of 0.00035 (indicating very low exploitation probability) and the vulnerability is not listed in CISA's KEV catalog. Exploitation would likely involve an attacker hosting malicious content that a user opens in Chrome; the crafted page must be delivered in a context where the renderer process is already compromised. Given the lack of known public exploits, the threat level remains high but unproven externally. This use‑after‑free is classified as both CWE‑416 and CWE‑825.
OpenCVE Enrichment