Impact
An information leakage flaw in the Skia graphics engine of Google Chrome allows a remote attacker to extract sensitive data and potentially circumvent the web origin policy with a crafted HTML page. The weakness stems from insufficient isolation of rendering contexts within Skia and is classified as CWE‑200, posing a threat to confidentiality by exposing private information that should be protected by same‑origin constraints. While the flaw does not grant arbitrary code execution, it undermines the security boundaries that browsers rely on to keep third‑party sites from accessing each other’s data.
Affected Systems
Google’s Chrome browser is affected, specifically any release prior to version 151.0.7922.169. All users running those older stable channel builds are at risk; desktop users on Windows, macOS, or Linux that have not updated to the patched release are included.
Risk and Exploitability
The vulnerability can be triggered remotely by serving a maliciously constructed HTML page, implying that an attacker only needs to lure a victim to a compromised site or to generate a phishing resource that references the page. The absence of an EPSS score and lack of listing in CISA KEV suggests that known exploit activity is minimal, yet the severity is high and the attack surface is wide. The exploit path requires standard web delivery, making prevention largely dependent on applying the vendor patch and tightening browser security controls.
OpenCVE Enrichment