Impact
The flaw resides in the SVG parsing path in Google Chrome, which allows a remote attacker to design a crafted HTML page that causes the browser to disclose data from other origins. This data leakage can expose sensitive information that should be protected by the same-origin policy, thereby compromising confidentiality. The weakness represents a failure in access control and aligns with information exposure defects. The CVE lists Chromium security severity as Medium.
Affected Systems
All installations of Google Chrome older than version 149.0.7827.53 are affected. The referenced release notes confirm that the issue is fixed in that and later builds, so any user or system currently running a prior build is vulnerable.
Risk and Exploitability
The vulnerability is not listed in the KEV catalog. Exploitation requires a remote attacker to persuade a user to visit a maliciously crafted site or host the page in a phishing context, making the attack vector likely remote via a web page. While the EPSS score is less than 1%, the CVSS score of 6.5 indicates a Medium severity, and the typical remote execution path suggests a moderate risk level for environments exposed to the public Internet.
OpenCVE Enrichment