Impact
The flaw is an information leak in the Canvas API of Google Chrome before version 152.0.7977.65. A malicious web page can craft a Canvas operation that causes the browser to expose pixel data belonging to content from another origin. This bypasses the same‑origin policy, allowing a remote attacker to read sensitive data that should be inaccessible. The weakness aligns with CWE-200 and is rated as a medium severity issue by Chromium.
Affected Systems
Google Chrome browsers running versions older than 152.0.7977.65 are vulnerable. The issue affects all stable channel releases of Chrome on desktop platforms prior to that version.
Risk and Exploitability
Based on the description, the likely attack vector is a crafted web page that triggers the browser to expose pixel data from a different origin, allowing an attacker to read data that should be protected by the same‑origin policy. The CVSS score is 4.3, indicating medium severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation is not currently documented. Because an attack requires only a user to visit a malicious site and no privileged software or elevated rights, the potential impact ranges from unauthorized data disclosure to possible session hijacking if sensitive information is stored within the canvas.
OpenCVE Enrichment
Debian DLA
Debian DSA