CVE-2026-76041: Infoleak
Published Aug 18, 2026
·Updated
Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Affected Software
2 affected components
Google Google Chrome<151.0.7922.169
Google Skia
Event History
Aug 18, 2026
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users running Google Chrome versions earlier than 151.0.7922.169 are potentially affected when they visit a crafted HTML page. The issue involves Skia and may allow a remote attacker to bypass web origin policy.
2
What does exploitation require?
The attacker needs to persuade a user to load a crafted HTML page in an affected Chrome version. No additional prerequisites are stated in the available information.
3
What should be done to remediate the issue?
Update Google Chrome to version 151.0.7922.169 or later. The provided information does not describe a temporary mitigation for systems that cannot yet be updated.