Junglewise Threat Intelligence

CVE-2026-17698: Google Chrome for Android improper input validation in UI

CVE-2026-17698 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android contains a security flaw in its user interface component that could allow a malicious website to access data from other websites. This type of vulnerability, known as a cross-origin data leak, could potentially expose sensitive user information or browsing activity to an attacker. Users should update their mobile browser to the latest version to mitigate this risk.

Technical details

A vulnerability exists in Google Chrome for Android due to improper input validation (CWE-20) within the User Interface (UI) component. An attacker could exploit this by convincing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation and leak data from other origins. The vulnerability was addressed in version 151.0.7922.72. While the NVD entry mentions a 'local' attacker, in the context of browser vulnerabilities, this typically refers to code execution within the local browser environment triggered by remote content.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-29: disclosed: Reported to Chromium project
  • 2026-07-29: patched: Stable channel update released
  • 2026-07-30: advisory: NVD publication date

References

Related threats