Cross-Origin Data Exposure in Google Chrome Skia Component
CVE-2026-19160

3.1LOW

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-19160?

An issue has been identified in the Skia component of Google Chrome, allowing a remote attacker who has compromised the renderer process to exploit an uninitialized use condition. This vulnerability can lead to an unauthorized disclosure of cross-origin data through a specially crafted HTML page. Users are advised to update their Google Chrome browsers to the latest version to mitigate potential risks associated with this security flaw.

Affected Version(s)

Chrome 151.0.7922.109

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.