CVE-2026-76041

Description

A flaw was found in chromium-browser. An information leak in the Skia component allows a remote attacker to potentially bypass the web origin policy by crafting a malicious HTML page. This could lead to unauthorized access to sensitive information across different web origins.

Statement

This is an Important information leak flaw in the Skia graphics engine, affecting Chromium and QtWebEngine components. A remote attacker could exploit this vulnerability by tricking a user into visiting a specially crafted HTML page, leading to a bypass of the web origin policy and potential unauthorized access to sensitive information. The user interaction requirement prevents a Critical rating, but the high confidentiality impact and scope change elevate it beyond Moderate.

Mitigation

Avoid visiting untrusted websites or opening untrusted HTML content. Users should exercise caution when browsing the internet and only access reputable sources to reduce the risk of exploitation.

Understanding the Weakness (CWE)

Access Control,Other

Technical Impact: Gain Privileges or Assume Identity; Varies by Context

An attacker can access any functionality that is inadvertently accessible to the source.

Frequently Asked Questions

Want to get errata notifications? Sign up here.