Impact
This vulnerability is an incorrect authorization of the Paint feature in Google Chrome that could allow a remote attacker to bypass the browser’s same‑origin policy. The flaw permits crafted HTML content to access or modify resources that should be restricted, potentially leading to data theft or injection of malicious scripts. The weakness is a classic resource‑authorization failure (CWE‑863).
Affected Systems
Affected products are Google Chrome browsers running any version older than 152.0.7977.65. The issue is discovered in the Paint component and applies to all clients that have not upgraded past this version at release 152.0.7977.65.
Risk and Exploitability
The CVSS score for this issue is 4.3, indicating a moderate level of severity. The EPSS score is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely a victim viewing a malicious crafted HTML page that triggers the Paint feature, resulting in a remote origin‑policy bypass. No public exploit is known, but the lack of a patch makes the risk theoretical but significant.
OpenCVE Enrichment
Debian DLA
Debian DSA