Executive brief
Google Chrome's Skia graphics engine contained an uninitialized resource that could be exploited by a remote attacker through a malicious HTML page. An attacker could bypass the browser's security model to read sensitive data from other websites, potentially exposing user credentials, personal information, or session tokens stored in browser memory.
Technical details
An uninitialized resource vulnerability exists in Google Chrome's Skia graphics rendering library prior to version 153.0.8010.47. The vulnerability allows a remote attacker to craft a malicious HTML page that, when visited, can access cross-origin data through the graphics engine without proper sanitization. The attack requires only user interaction (visiting a malicious website) with no additional authentication or privileges needed. Successful exploitation allows the attacker to read sensitive data from other origins, violating the browser's same-origin policy. Google classified this as High severity in Chromium and has patched the issue in Chrome 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Chrome 153.0.8010.47