Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its handling of Scalable Vector Graphics (SVG). An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute malicious code on the user's computer. While the browser's security sandbox provides some protection, this flaw represents a significant risk to the confidentiality and integrity of user data.
Technical details
A vulnerability exists in the SVG component of Google Chrome due to an inappropriate implementation related to object lifecycle management. The flaw allows a remote attacker to achieve arbitrary code execution within the browser's sandbox environment. To exploit this, an attacker must entice a user to load a maliciously crafted HTML page containing specific SVG elements. The issue is addressed in Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux. This vulnerability is tracked internally by Chromium as an object lifecycle issue (Issue 517309206).
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-28: disclosed: Reported internally by Google researchers
- 2026-06-08: patched: Fixed in Chrome Stable Channel Update 149.0.7827.102/.103
- 2026-06-09: advisory: NVD publication date