Impact
This vulnerability stems from inadequate policy enforcement for SVG files in Google Chrome versions earlier than 151.0.7922.72. A crafted HTML page can cause the browser to load an SVG that references cross‑origin data, enabling an attacker to access sensitive information that should be isolated by the browser’s same‑origin policy.
Affected Systems
Google Chrome users on versions before 151.0.7922.72 are affected. The issue was fixed in Chrome 151.0.7922.72 and later releases.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑severity information‑disclosure flaw, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attacks would require a victim to open a maliciously crafted HTML page that includes the vulnerable SVG, so the attack vector is client‑side exploitation via the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA