Impact
The vulnerability stems from an observable discrepancy in the rendering of SVG elements in Google Chrome versions before 152.0.7977.65, which allowed a remote attacker to retrieve data from a different origin by serving a specially crafted HTML page.
Affected Systems
Current Chrome releases are affected, specifically any Chrome desktop edition prior to 152.0.7977.65. The patch is included in the stable channel update released on August 5, 2026, bringing the browser to version 152.0.7977.65.
Risk and Exploitability
The CVSS score for this vulnerability is 4.3, indicating a medium severity impact. The EPSS score remains below 1%, suggesting a low likelihood of exploitation. The attack vector is remote, requiring a malicious web page that a user visits; the vulnerability has not yet been reported as exploited in the wild and is not listed in CISA's KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA