Junglewise Threat Intelligence

CVE-2026-17829: Google Chrome insufficient policy enforcement in Passwords

CVE-2026-17829 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its password management component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to access sensitive data from other websites the user has open. This could lead to the unauthorized disclosure of personal information or login credentials.

Technical details

A vulnerability exists in the Password management component of Google Chrome due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a malicious, specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak sensitive data from different origins. The issue is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for desktop
  • 2026-07-30: disclosed: NVD publication date

References

Related threats