Impact
A flaw in the Skia graphics library embedded in Google Chrome allows a remote attacker to obtain cross‑origin data by serving a specially crafted HTML page. This vulnerability permits the leakage of data from other origins, resulting in a medium‑severity information disclosure.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are affected. Users who continue to run any older release expose themselves to potential cross‑origin data leakage when visiting malicious or compromised web pages.
Risk and Exploitability
Chromium assigns a medium severity score of 4.3 on the CVSS scale, and the EPSS score is below 1 %. The vulnerability is not featured in the CISA KEV catalog, suggesting it has not been widely abused. Based on the description, it is inferred that exploitation requires the victim to load the crafted page in a vulnerable Chrome session; after that the attacker can read and exfiltrate cross‑origin data. The overall risk is moderate but could have significant privacy implications.
OpenCVE Enrichment
Debian DLA
Debian DSA