Impact
An incorrect authorization check in the Paint component of Google Chrome allows a remote attacker to craft an HTML page that reads data from cross‑origin sources. The vulnerability enables the attacker to obtain potentially sensitive information from a victim’s browser context without user interaction. The impact is exposure of data that the application should have protected, potentially leading to privacy violations and data breaches.
Affected Systems
Google Chrome versions prior to 153.0.8010.36. Any user running a version earlier than the patched release is at risk. The affected component is the Paint API, which can be invoked through standard HTML or JavaScript in malicious web pages.
Risk and Exploitability
The CVSS score of 4.3 indicates a lower severity, but the vulnerability still allows a remote attacker to obtain cross‑origin data from any web page the victim visits. The EPSS score is <1%, suggesting a low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Nonetheless, it can result in data leakage with minimal user interaction, so monitoring or mitigation is advised.
OpenCVE Enrichment
Debian DLA
Debian DSA