Junglewise Threat Intelligence

CVE-2026-17827: Google Chrome UXSS in CSS implementation

CVE-2026-17827 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its CSS implementation. This flaw could allow a malicious website to bypass security boundaries and execute unauthorized scripts or display fake content on other websites you have open. This type of attack, known as Universal Cross-Site Scripting (UXSS), can lead to the theft of sensitive information like login credentials or session cookies from unrelated web services.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's CSS implementation due to an inappropriate implementation flaw. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same-Origin Policy (SOP) and execute arbitrary JavaScript or HTML in the context of any website currently open in the browser. This issue is addressed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats