Junglewise Threat Intelligence

CVE-2026-17739: Google Chrome UXSS in Extensions

CVE-2026-17739 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its extension system. If an attacker convinces a user to install a malicious extension, they could inject unauthorized scripts or content into other websites the user visits. This could lead to the theft of sensitive information or unauthorized actions performed on the user's behalf across different web services.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability existed in Google Chrome's extension framework due to insufficient policy enforcement. The flaw allowed a specially crafted malicious extension to bypass security boundaries and inject arbitrary HTML or JavaScript into the context of other origins. Exploitation requires the attacker to successfully trick a user into installing the malicious extension (social engineering). Once installed, the extension can execute scripts across different websites, potentially leading to data exfiltration or session hijacking. The issue is resolved in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats