Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-17914 Side-channel information leakage in Skia
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5467
Acknowledgements:
Name: the Mozilla project Upstream: Heather Miller (Google Skia team)