High chrome UAF 🔧 Commit mapped

Overview

High
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactUse after free in Skia
DescriptionUse after free in Skia
ComponentSkia
Bug ClassUAF
Tracker553345874
Fix commitd7c15613590b (skia) +6/-1
CISA KEVNot listed
CreditedGoogle
Disclosed2026-09-03

Changed Functions

FunctionChangeNotes
if
src/core/SkCachedData.cpp
modified

Files Changed

  • src/core/SkCachedData.cpp
From d7c15613590bfe9f9a40e82542c2873766a2e558 Mon Sep 17 00:00:00 2001
From: Arthur Sonzogni <arthursonzogni@chromium.org>
Date: Thu, 27 Aug 2026 09:47:10 +0000
Subject: [PATCH] Fix UAF in SkCachedData::internalUnref

Destroy AutoMutexWritable before calling delete this in
SkCachedData::internalUnref to avoid unlocking the mutex after the
object has been deleted.

This was found while trying to enable the MiraclePtr rewrite
that would protect "this" and cause deterministic termination.
Fixed: 553345874
Bug: 351867706
Doc: https://bit.ly/miracleptr-skia
Change-Id: I0a1d3aed3b3d41e4ed06505295a14028ff634788
Reviewed-on: https://skia-review.googlesource.com/c/skia/+/1340596
Reviewed-by: Michael Ludwig <michaelludwig@google.com>
Commit-Queue: Arthur Sonzogni <arthursonzogni@chromium.org>
---

diff --git a/src/core/SkCachedData.cpp b/src/core/SkCachedData.cpp
index b48bee8..6df6d1d 100644
--- a/src/core/SkCachedData.cpp
+++ b/src/core/SkCachedData.cpp
@@ -65,7 +65,12 @@
 }
 
 void SkCachedData::internalUnref(bool fromCache) const {
-    if (AutoMutexWritable(this)->inMutexUnref(fromCache)) {
+    bool shouldDelete = false;
+    {
+        AutoMutexWritable amw(this);
+        shouldDelete = amw->inMutexUnref(fromCache);
+    }
+    if (shouldDelete) {
         // can't delete inside doInternalUnref, since it is locking a mutex (which we own)
         delete this;
     }
Loading diff…

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.