Impact
Google Chrome includes an SVG rendering engine that processes embedded vector graphics within web pages. A flaw allows a crafted SVG element inside a malicious HTML page to expose sensitive data that the user holds while the browser is focused. The vulnerability can reveal private information to a remote attacker. It is a medium‑severity weakness categorized as CWE-200, representing information exposure. The damage is limited to the user's session but may include credentials, clipboard contents, or other data that the browser can access.
Affected Systems
The affected product is Google Chrome for desktop. Versions prior to 154.0.8037.97 contain the flaw; later releases have a fix. The problem is not tied to any specific operating system, as Chrome runs across Windows, macOS, and Linux.
Risk and Exploitability
The CVSS score is rated medium, reflecting the need for the attacker to host a malicious web page that the user visits or the user to interact with. There is no publicly known exploit script, and the EPSS score is not available; however, the flaw is listed as Not in KEV, indicating moderate risk. The attack vector is likely remote via a crafted HTML page containing malicious SVG. An attacker would need the user to load the page while Chrome is active and the user has sufficient privileges that allow the browser to access the leaked data.
OpenCVE Enrichment