Impact
An inappropriate Skia implementation in Chrome versions prior to 148.0.7778.216 allows a remote attacker to extract potentially sensitive data from process memory through a crafted HTML page. The flaw presents a memory‑disclosure vulnerability that could expose confidential information such as credentials or tokens stored in the browser’s memory space.
Affected Systems
Google Chrome browsers on all supported platforms running any version earlier than 148.0.7778.216 are affected. Versions 148.0.7778.216 and newer contain the fix and are therefore not vulnerable.
Risk and Exploitability
Chromium classifies this as a high‑severity issue with a CVSS score of 6.5. The EPSS score is < 1% and it is not listed in the CISA KEV catalog, indicating no confirmed exploitation. The likely attack vector is a crafted HTML page that a user visits, enabling the flaw without elevated privileges. As a result, the risk is moderate for users who encounter such content.
OpenCVE Enrichment