Executive brief
Google Chrome's Canvas drawing component contained a security flaw that could allow malicious websites to extract sensitive data from other websites in the same browser. An attacker could craft a specially designed web page to read cross-origin data that should be protected, potentially exposing user information or content from other sites the user is visiting.
Technical details
The vulnerability is an information leak in the Canvas API of Google Chrome versions prior to 152.0.7977.65. A remote attacker can craft a malicious HTML page that exploits the Canvas implementation to read and leak cross-origin data that violates the browser's same-origin policy. The attack requires the user to visit the attacker's web page but does not require authentication or user interaction beyond normal browsing. The vulnerability was fixed in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79193 disclosed in Chrome 152 release notes
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)