Impact
Paint in Google Chrome exposes information before version 152.0.7977.65, enabling a remote attacker to bypass the web origin policy through a crafted HTML page. This flaw allows the attacker to read cross‑origin data that should remain inaccessible, compromising user confidentiality.
Affected Systems
All users running Google Chrome older than 152.0.7977.65 are affected. The vulnerability is specific to the Paint component and does not apply to newer releases where the fix is included.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3 and is not listed in the CISA KEV catalog. The EPSS score indicates a very low probability of exploitation, less than 1%. The likely attack vector requires a remote attacker to host a malicious web page that an affected user visits. Once accessed, the attacker can read protected information, though no direct remote code execution is provided.
OpenCVE Enrichment
Debian DLA
Debian DSA