Impact
Observable discrepancy in the Paint component of Google Chrome prior to version 155.0.8059.39 permits a remote attacker to construct a crafted HTML page that triggers the paint operation. The flaw causes cross‑origin data to be disclosed to the page, allowing the attacker to read information that should be inaccessible. This results in a confidentiality breach without requiring local code execution or privileged access.
Affected Systems
The issue affects Google Chrome browsers using the Paint API in releases before 155.0.8059.39. Systems running any earlier Chrome builds are susceptible until the specified update is applied.
Risk and Exploitability
The vulnerability is rated medium in Chromium’s internal severity, and no EPSS score is currently available, suggesting a moderate likelihood of exploitation. It is not listed in the CISA KEV catalog, which indicates that there have been no confirmed exploitation instances to date. Nevertheless, an attacker can exploit the flaw from a web page served over any network, making the threat surface significant for users who load untrusted content.
OpenCVE Enrichment