Executive brief
Google Chrome, a widely used web browser, contained a security flaw in its handling of Scalable Vector Graphics (SVG). This vulnerability could allow a malicious website to bypass security boundaries and access data from other websites you have open. While rated as low severity, it represents a breach of the browser's privacy protections that keep data from different sites isolated.
Technical details
A vulnerability classified as an inappropriate implementation existed in the SVG component of Google Chrome. The flaw allowed a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. The attack is executed via a specially crafted HTML page that, when visited by a user, leverages SVG processing to access information from other origins. This issue was addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date