Impact
A flaw in Skia within Google Chrome allows a remote attacker who has already compromised the renderer process to extract cross‑origin data by serving a specially crafted HTML page. The vulnerability leads to the disclosure of sensitive information without modifying system state or interrupting service. The weakness is identified as information exposure (CWE‑200).
Affected Systems
Google Chrome versions prior to 152.0.7977.75 are affected. Based on the description, it is inferred that the breach occurs in the Chrome stable channel on desktop platforms.
Risk and Exploitability
The CVSS base score is 3.1, and EPSS data is unavailable; the issue is not listed in CISA's KEV catalog. An attacker must first compromise the renderer process, after which a crafted HTML page can trigger the cross‑origin data leak. Based on the description, it is inferred that the overall threat is limited in scenarios where renderer processes are isolated from untrusted content, since the flaw does not alter system state and requires a renderer compromise before exploitation. This inference is derived directly from the described attack conditions rather than an assigned risk rating.
OpenCVE Enrichment
Debian DLA
Debian DSA