Executive brief
A vulnerability in Google Chrome's handling of SVG images could allow a malicious website to access data from other websites you have open. This type of 'cross-origin' leak can compromise user privacy by exposing information that should be restricted to a specific site. Users are protected by updating their browser to the latest version.
Technical details
An inappropriate implementation vulnerability exists in the SVG component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak sensitive data from other origins. The vulnerability is addressed in Chrome version 149.0.7827.53 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published to NVD