Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
To exploit the vulnerability, an attacker must first compromise the browser's renderer process (e.g., through a separate vulnerability). Then, using an appropriately crafted HTML page, they can exploit the improper implementation in the Skia graphics library to escape from the sandbox mechanism. This action goes beyond the isolated browser environment and can lead to interactions with the user's operating system.
An attacker who has previously compromised the renderer process can escape the browser sandbox and gain access to operating system resources – potentially leading to data disclosure, modification, or system destabilization.
Google Chrome should be updated to version 115.0.5790.98 or newer. The update is available through the browser's built-in update mechanism or on the manufacturer's website according to the references.
Google Chrome in versions earlier than 115.0.5790.98
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HGoogle Chrome
APPGoogle< 115.0.5790.98
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox