Impact
An observable discrepancy in the treatment of SVG elements within Google Chrome versions prior to 153.0.8010.36 allows a remote attacker to extract sensitive information through a crafted HTML page that embeds SVG content. The flaw is related to CWE-203, improper authorization, meaning the browser fails to enforce proper controls when processing SVG data, leading to an information disclosure.
Affected Systems
Affected systems include Google Chrome. Any installations using a Chrome build released before 153.0.8010.36 are susceptible to this vulnerability. No other versions or products from the vendor are impacted.
Risk and Exploitability
The risk profile is characterized by a CVSS score of 6.5, indicating moderate severity. The EPSS score of < 1% suggests a very low probability of exploitation. KEV does not list this issue. The likely attack vector is a malicious web page that the user loads, enabling the attacker to retrieve data hidden within the SVG structure. While the exploitation probability remains uncertain without substantial evidence, the potential for privacy compromise exists, especially if the user visits untrusted sites or opens crafted links.
OpenCVE Enrichment
Debian DLA
Debian DSA