CVE-2026-76041: Information leak in Skia
Chromium: CVE-2026-76041 Information leak in Skia
Other sources
Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.101 - Upgrade
Upgrade
Chromium/Google Chrome (Skia)to a version that resolves this vulnerability.Fixed in 151.0.7922.169
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Who is exposed to this issue?
Users running Google Chrome versions earlier than 151.0.7922.169 are potentially affected when they visit a crafted HTML page. The issue involves Skia and may allow a remote attacker to bypass web origin policy.
What does exploitation require?
The attacker needs to persuade a user to load a crafted HTML page in an affected Chrome version. No additional prerequisites are stated in the available information.
What should be done to remediate the issue?
Update Google Chrome to version 151.0.7922.169 or later. The provided information does not describe a temporary mitigation for systems that cannot yet be updated.