Junglewise Threat Intelligence

CVE-2026-17783: Google Chrome cross-origin data leak in Loader

CVE-2026-17783 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's content loading system could allow a malicious website to access data from other websites you have open. This bypasses standard security boundaries designed to keep information from different sites separate. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive user information.

Technical details

A cross-origin data leak vulnerability exists in the Loader component of Google Chrome. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries during certain resource loading operations. A remote attacker can exploit this by hosting a malicious HTML page that, when visited by a victim, leverages the loader's behavior to extract information from a different origin. This bypasses Same-Origin Policy (SOP) protections. The issue is resolved in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats