Description
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure through Skia rendering process
Action: Apply patch
AI Analysis

Impact

An information‑leak vulnerability exists in the Skia graphics library used by Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to read sensitive data from memory via a crafted HTML page, potentially exposing confidential material. The weakness is categorized as information disclosure (CWE-200).

Affected Systems

Google Chrome browsers that run the vulnerable Skia library, specifically those versions earlier than 152.0.7977.65. The issue was reported in the Chromium security tracker and is documented as impacting all installations using the default rendering path.

Risk and Exploitability

The vulnerability has a CVSS score of 5.3, reflecting low severity in Chromium’s metrics, and no high‑severity exploitation score is available. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog. Attackers would first need to compromise the renderer process, which likely requires a prior compromise of the browser or the host system. Once in place, they could execute crafted HTML to extract data, though this requires a sophisticated threat actor and is not trivially achievable from a remote network alone.

Generated by OpenCVE AI on August 26, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later on all affected machines.
  • Ensure Chrome automatic updates are enabled, or schedule a coordinated deployment of the patched version.
  • Monitor browser logs for unexpected rendering errors or attempts to read sensitive data from untrusted pages, and block those sources until the update is applied.

Generated by OpenCVE AI on August 26, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome Skia Render Process Information Leak Allows Sensitive Data Exposure

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Chrome Skia Render Process Information Leak Allows Sensitive Data Exposure

Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:36:16.714Z

Reserved: 2026-08-25T06:10:26.147Z

Link: CVE-2026-79147

cve-icon Vulnrichment

Updated: 2026-08-26T18:20:28.844Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:09.930

Modified: 2026-08-31T16:52:18.260

Link: CVE-2026-79147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor