Impact
The flaw allows an attacker who can supply a crafted web page to read data from a canvas that has rendered cross‑origin content, leaking confidential information. The weakness stems from improper access control over the canvas element, which is a classic Information Exposure problem (CWE‑200). The Chrome team rates the severity as Medium and the leak can violate the confidentiality of user data.
Affected Systems
Google Chrome, versions prior to 152.0.7977.65. The stable channel update that patches the issue is 152.0.7977.65 and newer releases.
Risk and Exploitability
A remote attacker can exploit the vulnerability by hosting or injecting a malicious HTML document that loads cross‑origin assets into a canvas. Because the attacker can read the resulting bitmap, the attacker can exfiltrate sensitive data such as credentials or private artwork. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the lack of KEV listing suggests exploitation hasn’t been observed yet. The CVSS score of 4.3 indicates a Medium severity according to the Common Vulnerability Scoring System. The severity remains Medium in Chromium, indicating a noticeable risk for users who visit malicious sites, though no known public exploits were documented at the time of analysis.
OpenCVE Enrichment
Debian DLA
Debian DSA