Chromium CVE-2026-85049: Use after free in Skia
Chromium: CVE-2026-79020 Out of bounds read in Skia
CVE-2026-19176 Use after free in Skia
Chromium: CVE-2026-13885 Use after free in Skia
Chromium: CVE-2026-3909 Out of bounds write in Skia
Chromium: CVE-2023-6347 Use after free in Mojo
SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).
Chromium: CVE-2023-6350 Out of bounds memory access in libavif
Chromium: CVE-2023-6351 Use after free in libavif
Chromium: CVE-2023-6348 Type Confusion in Spellcheck
Chromium: CVE-2023-6346 Use after free in WebAudio
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-30/#CVE-2018-18493
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5095