Impact
An improper implementation of SVG handling in Google Chrome prior to version 149.0.7827.103 allows a remote attacker to place a crafted HTML page that causes the browser to execute arbitrary code inside its sandbox. The flaw is a Code Injection weakness (CWE‑94) driven by inappropriate processing of SVG content, enabling code to run with the privileges of the sandboxed process and potentially exposing the system to compromise through browser‑based exploits.
Affected Systems
The vulnerability affects all Google Chrome installations using versions earlier than 149.0.7827.103. Users running any older release that may open a malicious web page embedding vulnerable SVG content are susceptible.
Risk and Exploitability
A remote attacker can deliver the exploit via a malicious website or document and trigger code execution in the browser sandbox, which may be leveraged to exfiltrate data or perform further attacks. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but its CVSS score of 8.8 indicates high severity and the widespread use of Chrome suggest a meaningful risk of exploitation in practice. The attack vector is likely through normal browsing of untrusted content.
OpenCVE Enrichment