Junglewise Threat Intelligence

CVE-2026-17820: Google Chrome cross-origin data leak in Autofill

CVE-2026-17820 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Autofill feature could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information stored in the browser. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An information disclosure vulnerability exists in the Autofill component of Google Chrome due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin boundaries and leak sensitive data from other origins. The vulnerability is addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats