Impact
An inappropriate implementation in Paint within Google Chrome allows a remote attacker to leak cross‑origin data by loading a specially crafted HTML page. The flaw means information that should be isolated to its origin can be unintentionally accessed, compromising the confidentiality of user data. This weakness is a typical information‑exposure vulnerability and can be exploited by any user who opens a malicious page in the affected browser.
Affected Systems
Google Chrome prior to version 149.0.7827.53 is vulnerable. All installations of the affected Chrome releases that enable the Paint component are at risk until they are upgraded to the fixed version or later.
Risk and Exploitability
The vulnerability was rated medium by the Chromium engineering team, indicating that an attacker can exploit it without needing elevated privileges or advanced techniques. No EPSS data is available and the flaw is not listed in the CISA KEV catalog, but because it can be triggered simply by visiting a crafted page, the likelihood of exploitation remains non‑negligible for users who interact with malicious websites. The primary attack vector is a remote HTML page that a user views in Chrome; thus any compromised or malicious site could trigger the data leak.
OpenCVE Enrichment