Description
Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Leak via SVG rendering
Action: Assess Impact
AI Analysis

Impact

Google Chrome includes an SVG rendering engine that processes embedded vector graphics within web pages. A flaw allows a crafted SVG element inside a malicious HTML page to expose sensitive data that the user holds while the browser is focused. The vulnerability can reveal private information to a remote attacker. It is a medium‑severity weakness categorized as CWE-200, representing information exposure. The damage is limited to the user's session but may include credentials, clipboard contents, or other data that the browser can access.

Affected Systems

The affected product is Google Chrome for desktop. Versions prior to 154.0.8037.97 contain the flaw; later releases have a fix. The problem is not tied to any specific operating system, as Chrome runs across Windows, macOS, and Linux.

Risk and Exploitability

The CVSS score is rated medium, reflecting the need for the attacker to host a malicious web page that the user visits or the user to interact with. There is no publicly known exploit script, and the EPSS score is not available; however, the flaw is listed as Not in KEV, indicating moderate risk. The attack vector is likely remote via a crafted HTML page containing malicious SVG. An attacker would need the user to load the page while Chrome is active and the user has sufficient privileges that allow the browser to access the leaked data.

Generated by OpenCVE AI on October 2, 2026 at 17:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 154.0.8037.97 or later.
  • If an immediate update is unavailable, configure the browser to block SVG rendering for external sites using Chrome policies.
  • Monitor user activity for the loading of untrusted SVG content and investigate any unexpected disclosures.

Generated by OpenCVE AI on October 2, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Title Information Leak via SVG in Google Chrome
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-02T16:07:56.619Z

Reserved: 2026-09-30T23:12:19.600Z

Link: CVE-2026-103627

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:43.827

Modified: 2026-10-02T17:47:56.067

Link: CVE-2026-103627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor