Junglewise Threat Intelligence

CVE-2026-17743: Google Chrome same origin policy bypass in ControlledFrame

CVE-2026-17743 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's ControlledFrame component, which is used to embed web content securely within applications. A remote attacker could use a specially crafted website to bypass the browser's Same-Origin Policy, a fundamental security mechanism that prevents websites from interacting with data from other sites. If exploited, this could allow an attacker to access sensitive information or perform unauthorized actions on behalf of the user across different web domains.

Technical details

A vulnerability classified as insufficient policy enforcement exists in the ControlledFrame component of Google Chrome. The flaw allows a remote attacker to bypass the Same-Origin Policy (SOP) by enticing a user to visit a maliciously crafted HTML page. By circumventing SOP, the attacker can potentially read data from or interact with web content in different origins that should be isolated. The issue is addressed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats