Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop.html | release notes vendor advisory |
https://crbug.com/1260250 | issue tracking permissions required vendor advisory exploit |