SVG — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 3, 2025
Last Seen
December 5, 2025

SVG (Scalable Vector Graphics) is an XML-based vector graphics standard used widely on the web to render images and animations.

Overview

SVG (Scalable Vector Graphics) is an XML-based vector graphics standard used widely on the web to render images and animations. In cybersecurity contexts, SVG can be abused to host overlays, scripts, or interactive content that bypasses UI defenses, enabling clickjacking and potential code execution within web applications. Recent reports highlight new SVG-based attack techniques that leverage CSS and SVG for advanced clickjacking, as well as a vulnerability in the Angular platform that allows code execution through crafted SVG animations, expanding the attack surface for web apps.

Related Threat Clusters

Recent Intelligence Reports

  • Novel clickjacking attack relies on CSS and SVG — Theregister · December 5, 2025
  • New SVG Clickjacking Attack Let Attackers Create Interactive Clickjacking Attacks — Cybersecuritynews · December 4, 2025
  • Angular Platform Vulnerability Lets Attackers Execute Code Through Malicious SVG Animations — Gbhackers · December 3, 2025

CVSS v3.1 Breakdown