Executive brief
A vulnerability in the Skia graphics engine used by Google Chrome could allow a malicious website to steal sensitive information from other websites you have open. This occurs if an attacker has already partially compromised the browser's rendering process, enabling them to bypass security boundaries that normally keep data from different sites separate. Users should update Chrome to the latest version to mitigate this risk.
Technical details
A vulnerability classified as an 'inappropriate implementation' exists within the Skia graphics library component of Google Chrome. The flaw allows a remote attacker to perform a cross-origin data leak. To exploit this, an attacker must first achieve a compromise of the renderer process (e.g., via a separate vulnerability). Once the renderer is compromised, the attacker can use a specially crafted HTML page to bypass Same-Origin Policy (SOP) protections and access data belonging to other origins. The issue is addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: CVE published to NVD