Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine, Skia, could allow a malicious website to access sensitive data from other websites you have open. This could lead to the theft of personal information or login credentials if a user visits a specially crafted web page.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Skia graphics component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass cross-origin isolation and read data from other memory locations. This can result in the exposure of sensitive information from different origins. The vulnerability was addressed in Chrome version 149.0.7827.53. While the NVD entry lists the severity as 'info', the Chromium project has classified this as a 'High' severity security issue.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published in NVD.