Executive brief
Google Chrome contains an information leak vulnerability in its Canvas rendering engine that allows remote attackers to read data across security boundaries. An attacker can craft a malicious HTML page that, when visited by a user, bypasses Chrome's web origin policy and leaks sensitive information from other websites. This could expose user session data, authentication tokens, or other confidential information from websites the user has visited.
Technical details
CVE-2026-78908 is an information leak vulnerability in the Canvas component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote attacker to bypass web origin policy restrictions through a crafted HTML page. The attack vector is network-based and requires only that a user visits a malicious webpage; no authentication or local access is required. An attacker can exploit this to read data that should be isolated by the same-origin policy, potentially exposing sensitive information from other origins. The vulnerability has been patched in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65