Junglewise Threat Intelligence

CVE-2026-17693: Google Chrome cross-origin data leak in FileSystem

CVE-2026-17693 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's FileSystem component could allow a malicious website to access data from other websites you have visited. This bypasses the browser's security boundaries that normally keep data from different sites separate. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the theft of sensitive personal or session information.

Technical details

This vulnerability is classified as an inappropriate implementation or insufficient policy enforcement within the FileSystem API of Google Chrome. The flaw allows for a cross-origin data leak, where a malicious origin can bypass Same-Origin Policy (SOP) restrictions to access data belonging to a different origin. The attack vector is remote, requiring a victim to navigate to a malicious or compromised website containing a crafted HTML page. Successful exploitation results in the unauthorized disclosure of sensitive information across site boundaries. Google has addressed this issue in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-28: disclosed: Reported to Chromium project
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats