Impact
An origin validation error in Paint allows a remote attacker to read data from a different origin by serving a specially crafted HTML page. Based on the description, it is inferred that a malicious webpage can instantiate a Paint object that loads cross‑origin data, exposing that data to the attacker. This flaw can be leveraged to obtain sensitive cross‑origin data, violating confidentiality. The vulnerability is classified as CWE‑346, improper origin validation. The issue receives a medium severity rating from Chromium's security team.
Affected Systems
The flaw exists in Google Chrome versions prior to 153.0.8010.36. The update to version 153.0.8010.36 or later incorporates the fix. All users of impacted Chrome releases are potentially at risk.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation. The CVSS score of 4.3 classifies the vulnerability as medium severity. The vulnerability has not been listed in the CISA KEV catalog, suggesting no known widespread exploitation. Attackers would need to host a malicious page that targets the vulnerable Paint implementation, typically from a remote web host; this attack vector is inferred from the description. The combined assessment points to a moderate risk, and users with standard browsing habits should consider the update timely to mitigate the disclosure risk.
OpenCVE Enrichment
Debian DLA
Debian DSA