Junglewise Threat Intelligence

CVE-2026-17775: Google Chrome cross-origin data leak in PresentationAPI

CVE-2026-17775 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Presentation API could allow a malicious website to access data from other websites you have open. This bypasses standard security boundaries that normally keep information from different sites separate. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive user information.

Technical details

A cross-origin data leak vulnerability exists in the Presentation API component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly enforce origin boundaries when handling presentation requests. A remote attacker can exploit this by hosting a malicious HTML page; when a user visits the page, the attacker can programmatically trigger API calls to leak information from other origins. This bypasses the Same-Origin Policy (SOP). The issue is resolved in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats