Impact
Chromium contains an integer overflow flaw in its Skia graphics library that can be triggered by a crafted HTML page. The overflow, classified as CWE‑190 and CWE‑472, allows a remote attacker who has already compromised the renderer process to execute arbitrary code within the sandboxing limits of Chrome.
Affected Systems
All desktop installations of Google Chrome using a version earlier than 148.0.7778.216 are vulnerable. This includes any user running the affected browser on Windows, macOS, or Linux.
Risk and Exploitability
The vulnerability is rated high with a CVSS score of 7.5. The EPSS score is less than 1%, indicating a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog, so no known exploitation has been reported. Exploitation requires the attacker to deliver a malicious web page that triggers the overflow, after which the renderer process is compromised and arbitrary code can run inside the sandbox.
OpenCVE Enrichment