Описание
Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
A flaw was found in Skia, a 2D graphics library utilized within Chromium-based browsers. A remote attacker, having already compromised the browser's renderer process, could exploit an out-of-bounds write vulnerability. This exploitation occurs by enticing a user to visit a specially crafted HTML page. The successful execution of this attack could enable the attacker to escape the browser's security sandbox, potentially leading to further compromise of the underlying system.
Отчет
An Important out-of-bounds write vulnerability in Skia, as used in various Red Hat components, allows a compromised browser renderer process to escape its security sandbox. This flaw requires user interaction to process a specially crafted HTML page. Successful exploitation could lead to further compromise of the underlying system beyond the browser's confines.
Дополнительная информация
Статус:
EPSS
9 Critical
CVSS3
Связанные уязвимости
Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 a ...
Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
EPSS
9 Critical
CVSS3