Description
Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an inappropriate implementation in the SVG component of Google Chrome. It allows a remote attacker to craft an HTML page that instructs the browser to load a specially constructed SVG object, bypassing the same‑origin policy. The result is a leak of data that originates from a different origin, exposing sensitive information such as authentication tokens or private content. This flaw is classified as CWE‑346.

Affected Systems

Affected releases include Google Chrome prior to version 151.0.7922.72. Any installation of Chrome that has not yet been updated to that release or later is vulnerable. The issue applies to all platforms that run Chrome with default SVG support enabled.

Risk and Exploitability

The CVSS score of 3.1 indicates a low severity disclosure risk, and the EPSS score of less than 1% suggests the likelihood of exploitation is low at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to host a malicious web page containing the crafted SVG payload and lure a user to visit the page. Because the flaw allows only information disclosure and requires a user‑initiated visit, widespread exploitation depends on the effectiveness of social engineering or phishing campaigns.

Generated by OpenCVE AI on August 4, 2026 at 23:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 151.0.7922.72 or later
  • If an immediate update is not possible, restrict or block inline SVG content in trusted contexts, for example by adding a Content‑Security‑Policy directive that disallows image/svg+xml or that removes SVG from the allowed sources
  • Monitor web traffic for attempts to serve malicious SVG files and educate users to recognize phishing attempts

Generated by OpenCVE AI on August 4, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in SVG
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 30 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T17:37:07.908Z

Reserved: 2026-07-27T23:34:33.253Z

Link: CVE-2026-17732

cve-icon Vulnrichment

Updated: 2026-07-30T17:37:04.356Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:35.930

Modified: 2026-08-03T17:45:30.457

Link: CVE-2026-17732

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:05Z

Links: CVE-2026-17732 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:15:07Z

Weaknesses