Junglewise Threat Intelligence

CVE-2026-17795: Google Chrome cross-origin data leak in GetUserMedia

CVE-2026-17795 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's media handling component could allow a malicious website to access data from other websites you have open. This occurs if an attacker has already partially compromised the browser's internal processing system. To protect against this, users should update Chrome to version 151.0.7922.72 or later.

Technical details

A vulnerability exists in the GetUserMedia implementation of Google Chrome due to improper input validation (CWE-20). A remote attacker who has already achieved code execution within a compromised renderer process can exploit this flaw to bypass cross-origin isolation. By enticing a user to visit a specially crafted HTML page, the attacker can leak sensitive data from other origins. The issue is resolved in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats