Junglewise Threat Intelligence

CVE-2026-17825: Google Chrome for Android policy bypass in Passwords

CVE-2026-17825 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used for accessing the internet. A security flaw in the browser's password management component could allow a malicious website to bypass security controls. This could potentially lead to unauthorized access to stored credentials or sensitive user information if a user visits a specially crafted webpage.

Technical details

An insufficient policy enforcement vulnerability exists in the Passwords component of Google Chrome for Android. The flaw allows a remote attacker to bypass discretionary access control (DAC) mechanisms by enticing a user to visit a specially crafted HTML page. This is categorized by Chromium as a Medium severity issue. Successful exploitation could allow an attacker to access or manipulate sensitive data managed by the password handler that should otherwise be protected by browser security policies. The issue is resolved in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats