Junglewise Threat Intelligence

CVE-2026-17942: Google Chrome side-channel information leakage in SVG

CVE-2026-17942 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, was found to have a security vulnerability in how it handles Scalable Vector Graphics (SVG). A remote attacker could use a specially crafted website to trick the browser into leaking information from other websites the user is visiting. While the risk is considered low, this could potentially allow an attacker to observe data that should be protected by the browser's security boundaries.

Technical details

A side-channel information leakage vulnerability exists in the SVG component of Google Chrome. The flaw, classified as CWE-1300 (Improper Protection of Physical Side Channels), allows a remote attacker to bypass cross-origin protections. By enticing a user to visit a malicious HTML page, the attacker can exploit timing or other side-channel behaviors during SVG rendering to infer data from a different origin. This vulnerability was addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats