Description
Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure with Origin Policy Bypass
Action: Apply Patch Now
AI Analysis

Impact

The vulnerability is an information leak within the Canvas API. A malicious HTML page can cause Chrome to expose pixel data from a canvas that has previously rendered resources from a different origin, thus violating the same‑origin policy. An attacker can read content that should be protected, compromising confidentiality and potentially gaining access to user data stored in the application or browser memory.

Affected Systems

Google Chrome for desktop, stable channel, versions earlier than 152.0.7977.65.

Risk and Exploitability

The vulnerability is remote, driven by a crafted HTML page delivered over HTTP/HTTPS. Because it relies only on existing canvas functionality, no special privilege or local code is required. The CVSS score of 4.3 indicates low severity while the possibility of leaking cross‑origin data remains. The EPSS score of less than 1% indicates an extremely low probability of exploitation, and the fact that it is unlisted in KEV suggests current exploitation activity is limited; however, the potential to compromise confidentiality warrants timely mitigation.

Generated by OpenCVE AI on August 28, 2026 at 19:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 152.0.7977.65 or later
  • If an update is not possible, restrict Canvas usage from untrusted origins by applying a restrictive Content Security Policy that disallows cross‑origin canvas reads
  • Consider disabling or blocking the Canvas API for untrusted content via browser policy or extensions

Generated by OpenCVE AI on August 28, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Canvas Information Leak Allows Web Origin Policy Bypass in Google Chrome

Fri, 28 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Canvas Information Leak Allows Web Origin Policy Bypass in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T20:37:09.166Z

Reserved: 2026-08-25T06:04:03.498Z

Link: CVE-2026-78908

cve-icon Vulnrichment

Updated: 2026-08-27T20:32:43.611Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:48.250

Modified: 2026-08-28T15:58:06.293

Link: CVE-2026-78908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor