Chrome · Skia
CVE-2026-79112
OOB in Skia
Overview
Low
Severity
—
CVSS
No
Exploited ITW
Fixed
Fix Status
Changed Functions
| Function | Change | Notes |
|---|---|---|
forsrc/core/SkTextBlob.cpp |
modified |
Files Changed
src/core/SkTextBlob.cpp
Patch
From 9468e96cc40f6c18e62caf9a4b4a0a700fa7f24a Mon Sep 17 00:00:00 2001
From: Alexis Cruz-Ayala <alexisdavidc@google.com>
Date: Fri, 17 Jul 2026 09:55:43 -0400
Subject: [PATCH] [Security] Added checks to MakeFromBuffer for Cluster size
If a renderer is compromised, an OOB cluster index can be provided, which would then lead to an OOB memory read if it underflows / overflows.
The solution is to check each glyph within the clusters array (buf->clusters) when deserializing such taht all cluster indices are not greater than textsize. Otherwise return nullptr.
Bug: b/524864599
Change-Id: Ib30a36a42ff4509533297eabd4eadfd6168f349a
Reviewed-on: https://skia-review.googlesource.com/c/skia/+/1295057
Reviewed-by: Florin Malita <fmalita@google.com>
Commit-Queue: Alexis Cruz-Ayala <alexisdavidc@google.com>
---
diff --git a/src/core/SkTextBlob.cpp b/src/core/SkTextBlob.cpp
index 6695a39..c95badb 100644
--- a/src/core/SkTextBlob.cpp
+++ b/src/core/SkTextBlob.cpp
@@ -778,6 +778,12 @@
!reader.readByteArray(buf->utf8text, textSize)) {
return nullptr;
}
+
+ for (int i = 0; i < glyphCount; ++i) {
+ if (buf->clusters[i] >= static_cast<uint32_t>(textSize)) {
+ return nullptr;
+ }
+ }
}
}
Loading diff…
Original Bug Report
The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.
References
On This Page