Junglewise Threat Intelligence

CVE-2026-17753: Google Chrome cross-origin data leak in Autofill

CVE-2026-17753 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Autofill feature could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information stored in the browser. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists in the Autofill component of Google Chrome prior to version 151.0.7922.72. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by enticing a user to visit a specially crafted HTML page. Successful exploitation enables the attacker to leak sensitive data from different origins (cross-origin data) that the browser has stored or is currently processing. This issue is categorized by Chromium as Medium severity and has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats