Executive brief
Google Chrome's Paint component contains an origin validation flaw that allows attackers to bypass cross-origin protections through a specially crafted HTML page. An attacker could exploit this to steal sensitive data from other websites that users have open in their browser, compromising user privacy and data security.
Technical details
This vulnerability is an origin validation error in Chrome's Paint component that fails to properly enforce cross-origin policies. An attacker can craft a malicious HTML page that, when opened in a victim's browser, bypasses the browser's same-origin policy to access data from other origins. The attack requires only that a user visit the attacker's crafted page while having other sensitive websites open in the same browser. The vulnerability is fixed in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released