Executive brief
Google Chrome, a widely used web browser, contained a security flaw in how it handles Scalable Vector Graphics (SVG) files. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to access sensitive data from other websites the user has open. This could lead to the unauthorized disclosure of personal information or login session details.
Technical details
A vulnerability exists in Google Chrome's SVG implementation due to insufficient policy enforcement. A remote attacker can exploit this by hosting a malicious HTML page that, when visited by a victim, leverages crafted SVG content to bypass cross-origin restrictions. This allows the attacker to leak sensitive data from different origins (cross-origin data leakage). The issue is resolved in Google Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date