Junglewise Threat Intelligence

CVE-2026-17963: Google Chrome cross-origin data leak in SVG

CVE-2026-17963 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its handling of Scalable Vector Graphics (SVG). This vulnerability could allow a malicious website to bypass security boundaries and access data from other websites you have open. While rated as low severity, it represents a breach of the browser's privacy protections that keep data from different sites isolated.

Technical details

A vulnerability classified as an inappropriate implementation existed in the SVG component of Google Chrome. The flaw allowed a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. The attack is executed via a specially crafted HTML page that, when visited by a user, leverages SVG processing to access information from other origins. This issue was addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats