Impact
Insufficient enforcement of the SVG policy in Google Chrome versions prior to 150.0.7871.47 allows a remotely crafted HTML page to trigger a cross‑origin data leak. The flaw is rooted in a policy intended to restrict access that is not properly applied, enabling a page to read content from domains that the browser normally treats as protected. This weakness corresponds to CWE‑346 and can lead to disclosure of sensitive data such as user credentials or session information.
Affected Systems
Google Chrome versions older than 150.0.7871.47 are affected. The issue originates in the stable channel’s core rendering engine. No information is provided about specific operating systems.
Risk and Exploitability
Chromium assigns a CVSS score of 6.5, reflecting moderate severity. The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of current exploitation. The likely attack vector is a malicious web page that hosts a crafted SVG; the policy breach occurs as the page loads, enabling exfiltration of cross‑origin data.
OpenCVE Enrichment
Debian DLA
Debian DSA