Impact
A flaw in the Canvas rendering subsystem of Google Chrome before version 150.0.7871.47 allows a remote attacker to bypass the browser’s same‑origin policy by using a malicious web page that reads pixel data from a different origin, resulting in the exposure of sensitive data. The issue is related to CWE‑346 (insufficient policy enforcement), reflecting risks of leaking protected data through misconfigured access controls.
Affected Systems
All desktop installations of Google Chrome running any version earlier than 150.0.7871.47 are affected; the issue has been fixed in that revision.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. The EPSS score is below 1 %, suggesting a very low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to convince a user to load a specially crafted web page, either locally or remotely; no widespread exploitation has been reported.
OpenCVE Enrichment
Debian DLA
Debian DSA