Junglewise Threat Intelligence

CVE-2026-17833: Google Chrome cross-origin data leak in Passwords

CVE-2026-17833 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's password management component could allow a malicious website to access data from other websites. If a user visits a specially crafted webpage, an attacker could potentially leak sensitive cross-origin information. This poses a risk to user privacy and the confidentiality of data handled by the browser.

Technical details

An inappropriate implementation vulnerability exists within the Passwords component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation boundaries and leak sensitive data. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Chromium developers have assigned this a Medium severity rating.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats