Junglewise Threat Intelligence

CVE-2026-17734: Google Chrome UXSS in Autofill

CVE-2026-17734 · Severity: info · CVSS 6.1 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Autofill feature, which automatically completes forms for users, contains a security flaw that could allow a malicious website to run unauthorized scripts in the context of other sites. If a user visits a specially crafted webpage, an attacker could potentially steal sensitive information or perform actions on the user's behalf on different websites. This type of attack, known as Universal Cross-Site Scripting (UXSS), bypasses the standard security boundaries that keep websites isolated from one another.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Autofill component of Google Chrome prior to version 151.0.7922.72. The flaw stems from an inappropriate implementation that fails to properly isolate or sanitize interactions during the autofill process. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the injection of arbitrary scripts or HTML into different origins. This bypasses the Same-Origin Policy (SOP), potentially leading to the disclosure of sensitive session data or unauthorized actions across multiple web domains. Google has addressed this issue in the stable channel update for desktop.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats