Impact
The vulnerability is an insufficient enforcement of SVG policy in Google Chrome prior to version 150.0.7871.47, which allows a crafted SVG element embedded in a web page to bypass the same‑origin restriction and read data belonging to another domain. This flaw results in a cross‑origin data leak and is identified as CWE‑346.
Affected Systems
All users running Google Chrome older than 150.0.7871.Windows, macOS, Linux, and Chrome OS—are potentially affected. The issue originates from a bug in the stable channel's core rendering engine, meaning every release prior to the fix carries the flaw.
Risk and Exploitability
Chromium rates this issue as high severity with a CVSS score of 6.5. The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of current exploitation. The likely attack vector is a malicious web page containing a crafted SVG that a victim must visit; the policy breach occurs as the page loads, enabling exfiltration of cross‑origin data. It is inferred that the victim needs no additional actions beyond navigating to the page.
OpenCVE Enrichment
Debian DLA
Debian DSA