Junglewise Threat Intelligence

CVE-2026-11180: Google Chrome cross-origin data leak in SVG

CVE-2026-11180 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its handling of SVG (Scalable Vector Graphics) images could allow a malicious website to access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information across different web domains.

Technical details

An information disclosure vulnerability exists in the SVG implementation of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly enforce cross-origin boundaries when processing SVG content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to leak data from other origins. This bypasses the Same-Origin Policy (SOP) which is a fundamental security model in web browsers. The issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome Stable Channel Update for Desktop released version 149.0.7827.53
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats