Junglewise Threat Intelligence

CVE-2026-17700: Google Chrome improper input validation in Actor

CVE-2026-17700 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome could allow a remote attacker to access sensitive data from other websites. This issue occurs when the browser fails to properly validate information, potentially allowing an attacker who has already partially compromised the browser's rendering engine to bypass security boundaries. If exploited, this could lead to the unauthorized exposure of user data across different web domains.

Technical details

An improper input validation vulnerability (CWE-20) exists in the 'Actor' component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass cross-origin isolation. By enticing a user to visit a specially crafted HTML page, the attacker can leak sensitive data from other origins. This vulnerability is addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-29: disclosed: Reported to Chromium by Google researchers
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats