Junglewise Threat Intelligence

CVE-2026-17815: Google Chrome insufficient policy enforcement in GuestView

CVE-2026-17815 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its GuestView component. This component is responsible for displaying content from one website inside another, such as in browser extensions or specific web apps. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to steal sensitive information from other websites the user has open.

Technical details

A vulnerability classified as insufficient policy enforcement exists within the GuestView component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by utilizing a specially crafted HTML page. By exploiting this weakness, an attacker can potentially access and leak data from different origins that should be protected by the browser's security model. The issue is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. No user authentication is required for exploitation, though it does require the victim to navigate to an attacker-controlled page.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats