Junglewise Threat Intelligence

CVE-2026-78895: Google Chrome information leak in Paint

CVE-2026-78895 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Paint component contains an information leak vulnerability that allows a remote attacker to bypass web origin policy through a crafted HTML page. This could enable attackers to extract sensitive data across security boundaries that should protect user privacy and prevent cross-site attacks, potentially exposing user information to malicious websites.

Technical details

The vulnerability is an information leak in Chrome's Paint component (CVE-2026-78895) that allows bypassing the same-origin policy through a specially crafted HTML page. The attack is network-based and requires only that a user visit or be directed to a malicious webpage—no authentication or user interaction beyond normal browsing is required. An attacker can leverage this to extract sensitive data that should be isolated between different web origins. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats