Executive brief
Google Chrome contains a flaw in how it renders SVG (Scalable Vector Graphics) images that can leak sensitive information. An attacker can craft a malicious webpage that exploits this discrepancy to extract data a user might not expect to be visible, potentially exposing personal or confidential information.
Technical details
An observable discrepancy vulnerability exists in Chrome's SVG rendering engine that allows information disclosure through crafted HTML pages. The vulnerability is triggered when a user visits a malicious webpage containing specially crafted SVG content. The attack requires no authentication and is delivered via the network. An attacker can exploit this to obtain sensitive information that should otherwise remain hidden or restricted. The vulnerability has been fixed in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released