Junglewise Threat Intelligence

CVE-2026-79144: Google Chrome information leak in Skia

CVE-2026-79144 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Skia graphics engine contained a flaw that allowed attackers to steal sensitive data from other websites through a malicious webpage. An attacker could craft a specially designed HTML page to extract cross-origin data that should be protected by browser security boundaries, potentially exposing user information or website content.

Technical details

This is an information disclosure vulnerability in the Skia graphics rendering engine used by Chrome. The flaw allows a remote attacker to obtain cross-origin data via a crafted HTML page, bypassing the same-origin policy that normally prevents websites from accessing each other's data. The vulnerability is reachable via network through opening a malicious webpage—no authentication or user interaction beyond visiting a page is required. An attacker can extract sensitive data from other domains or websites the user has open. The vulnerability was patched in Chrome version 152.0.7977.65.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Published via Chrome Releases blog
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats