Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
The vulnerability consists of an integer overflow error in the Skia component — a 2D graphics engine used by Chrome to render content. An attacker can provide a specially crafted HTML page whose processing triggers incorrect arithmetic calculations leading to overflow. This results in unpredictable memory behavior that can be exploited to break out of the browser's isolated execution environment (sandbox). CWE-472 indicates improper handling of externally controlled numerical values.
An attacker may potentially execute a Chrome sandbox escape, which can lead to execution of malicious code outside the browser environment, and consequently to taking control over the victim's system.
Google Chrome should be updated to version 150.0.7871.46 or newer. The update is available through Chrome's built-in update mechanism or on the manufacturer's website according to the references.
Google Chrome versions earlier than 150.0.7871.46
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HGoogle Chrome
APPGoogle< 150.0.7871.46
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Type confusion w V8 (Google Chrome/Edge) umożliwiający heap corruption
Type Confusion w V8 (Google Chrome) — RCE przez spreparowaną stronę HTML
Type Confusion w silniku V8 Chrome — zdalne wykonanie kodu (RCE)
Use-after-free w Google Chrome Visuals umożliwiający ucieczkę z sandbox