Junglewise Threat Intelligence

CVE-2026-17817: Google Chrome cross-origin data leak in ReportingAndNEL

CVE-2026-17817 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its reporting and network error logging components could allow a malicious website to access data from other websites you have visited. This type of information leak can compromise user privacy by exposing sensitive data across different web domains.

Technical details

A vulnerability exists in the Reporting and Network Error Logging (NEL) implementation of Google Chrome. The flaw is categorized as an inappropriate implementation that fails to properly enforce cross-origin boundaries. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, which then triggers the leak of sensitive data from other origins. This bypasses the Same-Origin Policy (SOP) protections intended to keep data from different sites isolated. The issue is resolved in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats