Description
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑origin information disclosure
Action: Patch
AI Analysis

Impact

A flaw in the Skia graphics library embedded in Google Chrome allows a remote attacker to obtain cross‑origin data by serving a specially crafted HTML page. This vulnerability permits the leakage of data from other origins, resulting in a medium‑severity information disclosure.

Affected Systems

Google Chrome versions prior to 152.0.7977.65 are affected. Users who continue to run any older release expose themselves to potential cross‑origin data leakage when visiting malicious or compromised web pages.

Risk and Exploitability

Chromium assigns a medium severity score of 4.3 on the CVSS scale, and the EPSS score is below 1 %. The vulnerability is not featured in the CISA KEV catalog, suggesting it has not been widely abused. Based on the description, it is inferred that exploitation requires the victim to load the crafted page in a vulnerable Chrome session; after that the attacker can read and exfiltrate cross‑origin data. The overall risk is moderate but could have significant privacy implications.

Generated by OpenCVE AI on September 5, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later.
  • Apply a strict Content Security Policy that restricts cross‑origin data access for untrusted content.
  • Use a separate browser profile or isolated browsing environment for sensitive web interactions until the patch is applied.

Generated by OpenCVE AI on September 5, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Sat, 05 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: skia: chromium-browser: Information leak in Skia
Weaknesses CWE-346
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Skia Information Leak in Chrome Allowing Remote Cross‑Origin Data Access

Wed, 26 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Skia Information Leak in Chrome Allowing Remote Cross‑Origin Data Access

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T19:56:37.022Z

Reserved: 2026-08-25T06:10:24.299Z

Link: CVE-2026-79144

cve-icon Vulnrichment

Updated: 2026-08-26T19:48:00.089Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:09.717

Modified: 2026-08-31T16:52:22.960

Link: CVE-2026-79144

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-25T20:10:18Z

Links: CVE-2026-79144 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T01:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-346

    Origin Validation Error