Junglewise Threat Intelligence

CVE-2026-17732: Google Chrome cross-origin data leak in SVG

CVE-2026-17732 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its handling of Scalable Vector Graphics (SVG). This flaw could allow a malicious website to bypass security boundaries and access data from other websites you have open. If exploited, an attacker could potentially steal sensitive information, such as login tokens or personal data, from different web services by tricking a user into visiting a specially crafted page.

Technical details

An inappropriate implementation vulnerability exists in the SVG component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. The attack is delivered via a crafted HTML page that, when visited by a user, leverages SVG processing to access information from other origins. This issue was addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Access to specific bug details remains restricted by the Chromium team to prevent further exploitation until a majority of users have updated.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats