Executive brief
A vulnerability in Google Chrome's handling of SVG (Scalable Vector Graphics) images could allow a malicious website to access data from other websites you have open. This type of 'cross-origin' leak can compromise user privacy by exposing information that should be restricted to a specific site. Users should update to the latest version of Chrome to protect their browsing data.
Technical details
An information disclosure vulnerability exists in the SVG implementation of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly enforce cross-origin boundaries when processing SVG content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to leak sensitive data from different origins. This is categorized by Chromium as Medium severity and was addressed in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47
- 2026-06-30: advisory