Junglewise Threat Intelligence

CVE-2026-17788: Google Chrome cross-origin data leak in Blink

CVE-2026-17788 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Blink rendering engine could allow a malicious website to access data from other websites you have open. This bypasses the browser's security boundaries that normally keep data from different sites separate. An attacker could exploit this by tricking a user into visiting a specially crafted web page, potentially leading to the unauthorized disclosure of sensitive information.

Technical details

An inappropriate implementation in the Blink rendering engine in Google Chrome allowed a remote attacker to leak cross-origin data. The vulnerability stems from a failure to properly enforce same-origin policy boundaries within the rendering component. By enticing a user to visit a malicious website, an attacker can use a crafted HTML page to extract information from other origins. This is classified as a cross-origin information leak. The issue is resolved in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-07-30: disclosed: NVD publication date.

References

Related threats