Junglewise Threat Intelligence

CVE-2026-17765: Google Chrome inappropriate implementation in WebProtect

CVE-2026-17765 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's WebProtect component, which is responsible for safeguarding user data during web browsing. If an attacker has already partially compromised the browser's rendering process, they could use a specially crafted webpage to steal sensitive information from other websites the user has open. This could lead to the exposure of private data, such as login tokens or personal information, across different web domains.

Technical details

This vulnerability is classified as an inappropriate implementation within the WebProtect component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation boundaries. To exploit this, an attacker must first achieve code execution within a compromised renderer process. Once the renderer is compromised, the attacker can use a crafted HTML page to leak sensitive data from other origins (cross-origin data). The issue is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats