Junglewise Threat Intelligence

CVE-2026-17662: Google Chrome cross-origin data leak in Prefetch

CVE-2026-17662 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its prefetch mechanism—which speeds up browsing by loading resources before they are requested—could allow a malicious website to access data from other websites. This could lead to the unauthorized exposure of sensitive user information across different web domains.

Technical details

An information disclosure vulnerability exists in Google Chrome's Prefetch component due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak sensitive data from other origins. The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-03-29: disclosed: Reported to Chromium project by Google internal researchers
  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats