An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5159