PT-2025-43503 · Unknown · Skiarenderengine

Published

2025-10-23

·

Updated

2026-03-06

·

CVE-2025-48630

CVSS v3.1

7.4

High

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SkiaRenderEngine (affected versions not specified)
Description A flaw exists in the drawLayersInternal function within SkiaRenderEngine.cpp that may allow access to the GPU cache, potentially revealing side channel information. This could lead to local privilege escalation without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ASB-A-455563813
CVE-2025-48630

Affected Products

Skiarenderengine