Impact
In versions of Google Chrome before 153.0.8010.52, an improper state validation flaw in the Skia graphics library could be triggered by a specially crafted HTML page. This flaw involves CWE-346 (Improper Validation of State) and allows a remote attacker to bypass origin restrictions and read data that the page should not access, a violation of CWE-754 (Improper Access Control). The resulting data extraction undermines confidentiality and can expose sensitive information that a user had loaded from a protected origin.
Affected Systems
Google Chrome browsers that are out of date, specifically all desktop builds earlier than version 153.0.8010.52. The vulnerability is tied to the Chromium Skia component and affects all platforms that ship this Chrome release.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity, and the EPSS score of less than 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need to lure a user to a malicious web page that contains the crafted payload; the operation does not require elevated privileges or local code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA