Impact
An information leakage flaw in the Skia graphics engine of Google Chrome allows a remote attacker to extract sensitive data and potentially circumvent the web origin policy with a crafted HTML page. The weakness stems from insufficient isolation of rendering contexts within Skia and is classified as CWE‑200, posing a threat to confidentiality by exposing private information that should be protected by same‑origin constraints. While the flaw does not grant arbitrary code execution, it undermines the security boundaries that browsers rely on to keep third‑party sites from accessing each other’s data.
Affected Systems
Google’s Chrome browser is affected, specifically any release prior to version 151.0.7922.169. All users running those older stable channel builds are at risk; desktop users on Windows, macOS, or Linux that have not updated to the patched release are included.
Risk and Exploitability
The vulnerability can be triggered remotely by serving a maliciously constructed HTML page, implying that an attacker only needs to lure a victim to a compromised site or to generate a phishing resource that references the page. The flaw, classified as CWE‑200 (Information Exposure) and CWE‑346 (Out‑of‑Bounds Write), leverages Skia’s rendering context isolation weaknesses, preventing proper enforcement of same‑origin policy. The EPSS score of <1% indicates few known exploitations; however, the CVSS score of 4.3 suggests a moderate severity rating. It is not listed in the CISA KEV catalog. The attack path requires only standard web delivery, making prevention largely dependent on applying the vendor patch and tightening browser security controls.
OpenCVE Enrichment
Debian DLA
Debian DSA