Junglewise Threat Intelligence

CVE-2026-78987: Google Chrome information leak in Canvas via origin bypass

CVE-2026-78987 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Canvas component contains an information leak vulnerability that allows an attacker to bypass the browser's web origin policy (a core security boundary that prevents malicious websites from accessing data from other sites) by hosting a specially crafted HTML page. An attacker can exploit this to steal sensitive information from other websites that a user visits, potentially exposing passwords, session data, or personal information.

Technical details

The vulnerability is an information leak in the Canvas rendering component of Google Chrome that allows an attacker to bypass the Same-Origin Policy (SOP) through a crafted HTML page. The attack vector is network-based and requires user interaction (user must visit the attacker's malicious webpage). An attacker can retrieve sensitive pixel data or other information from Canvas elements belonging to cross-origin websites, leading to confidentiality breach. The vulnerability affects Chrome versions prior to 152.0.7977.65, and is patched in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats