Executive brief
Google Chrome is a widely used web browser. A vulnerability in its handling of SVG (Scalable Vector Graphics) images could allow a malicious website to access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information across different web domains.
Technical details
An information disclosure vulnerability exists in the SVG implementation of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly enforce cross-origin boundaries when processing SVG content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to leak data from other origins. This bypasses the Same-Origin Policy (SOP) which is a fundamental security model in web browsers. The issue is resolved in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome Stable Channel Update for Desktop released version 149.0.7827.53
- 2026-06-04: disclosed: CVE published to NVD