Description
Observable discrepancy in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Origin Data Leak
Action: Immediate Patch
AI Analysis

Impact

Observable discrepancy in the Paint component of Google Chrome prior to version 155.0.8059.39 permits a remote attacker to construct a crafted HTML page that triggers the paint operation. The flaw causes cross‑origin data to be disclosed to the page, allowing the attacker to read information that should be inaccessible. This results in a confidentiality breach without requiring local code execution or privileged access.

Affected Systems

The issue affects Google Chrome browsers using the Paint API in releases before 155.0.8059.39. Systems running any earlier Chrome builds are susceptible until the specified update is applied.

Risk and Exploitability

The vulnerability is rated medium in Chromium’s internal severity, and no EPSS score is currently available, suggesting a moderate likelihood of exploitation. It is not listed in the CISA KEV catalog, which indicates that there have been no confirmed exploitation instances to date. Nevertheless, an attacker can exploit the flaw from a web page served over any network, making the threat surface significant for users who load untrusted content.

Generated by OpenCVE AI on October 6, 2026 at 22:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or later, which includes the Paint API fix.
  • If an immediate update is not possible, configure browser settings or use Chrome flags to block the Paint API for untrusted HTML content, thereby preventing the cross‑origin leakage.
  • Ensure your organization’s update management processes enforce automatic or timely distribution of the patched Chrome releases, and monitor for future security advisories.

Generated by OpenCVE AI on October 6, 2026 at 22:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via Paint in Google Chrome
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-203
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T21:16:15.939Z

Reserved: 2026-10-06T16:35:40.742Z

Link: CVE-2026-106336

cve-icon Vulnrichment

Updated: 2026-10-06T21:11:17.561Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:02.020

Modified: 2026-10-06T22:17:03.467

Link: CVE-2026-106336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:15:06Z

Weaknesses