Impact
The vulnerability is an information leak within the Canvas API. A malicious HTML page can cause Chrome to expose pixel data from a canvas that has previously rendered resources from a different origin, thus violating the same‑origin policy. An attacker can read content that should be protected, compromising confidentiality and potentially gaining access to user data stored in the application or browser memory.
Affected Systems
Google Chrome for desktop, stable channel, versions earlier than 152.0.7977.65.
Risk and Exploitability
The vulnerability is remote, driven by a crafted HTML page delivered over HTTP/HTTPS. Because it relies only on existing canvas functionality, no special privilege or local code is required. The CVSS score of 4.3 indicates low severity while the possibility of leaking cross‑origin data remains. The EPSS score of less than 1% indicates an extremely low probability of exploitation, and the fact that it is unlisted in KEV suggests current exploitation activity is limited; however, the potential to compromise confidentiality warrants timely mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA