Junglewise Threat Intelligence

CVE-2026-17733: Google Chrome for Android cross-origin data leak in QUIC

CVE-2026-17733 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome browser for Android could allow a malicious website to access data from other websites you have open. This occurs due to a flaw in how the browser handles the QUIC networking protocol. An attacker could exploit this by tricking a user into visiting a specially crafted web page, potentially leading to the unauthorized disclosure of sensitive information.

Technical details

A cross-origin data leak vulnerability exists in the QUIC implementation of Google Chrome for Android. The flaw stems from an inappropriate implementation of the protocol, which fails to properly isolate data between different origins. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page that, when visited by a victim, triggers the leak of sensitive information from other origins. This issue was addressed in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats