Executive brief
Google Chrome's Paint component contained an authorization flaw that allowed attackers to access sensitive data from different websites through a crafted HTML page. An attacker could exploit this to steal cross-origin information without proper permission, potentially exposing user data and violating web security boundaries that protect sensitive information on different sites.
Technical details
An incorrect authorization vulnerability exists in the Paint component of Google Chrome prior to version 153.0.8010.36. The flaw allows a remote attacker to bypass cross-origin restrictions and read data from other origins by serving a specially crafted HTML page. The attack requires user interaction (visiting a malicious page) and operates over the network via a web browser. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026. No evidence of active exploitation in the wild has been reported as of the advisory date.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36
- 2026-09-09: disclosed