Junglewise Threat Intelligence

CVE-2026-13793: Google Chrome insufficient policy enforcement in SVG

CVE-2026-13793 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security vulnerability in its handling of Scalable Vector Graphics (SVG). An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to steal sensitive information from other websites the user has open. This could lead to the exposure of private user data or session information across different web domains.

Technical details

A vulnerability classified as insufficient policy enforcement exists in the SVG component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin resource sharing (CORS) or similar security boundaries to leak data from different origins. The attack is executed via a crafted HTML page that, when rendered by the browser, triggers the improper enforcement logic. This issue was addressed in Chrome version 150.0.7871.47. The vulnerability was reported by an external researcher and assigned a 'High' severity rating by the Chromium project.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-05-07: disclosed: Reported to Chromium project
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
  • 2026-06-30: advisory: NVD publication date

References

Related threats