Junglewise Threat Intelligence

CVE-2026-17843: Google Chrome cross-origin data leak in CSS

CVE-2026-17843 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's CSS engine could allow a malicious website to bypass security boundaries and access data from other websites you have open. This type of 'cross-origin' leak can lead to the exposure of sensitive information, such as login tokens or personal details, if a user visits a specially crafted page. Google has released an update to address this issue, and users should ensure their browser is updated to the latest version.

Technical details

A cross-origin information leak vulnerability exists in Google Chrome's CSS implementation prior to version 151.0.7922.72. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries when processing certain CSS properties or selectors. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, which then uses crafted CSS to probe or extract data from a different origin. This is classified by Chromium as a Medium severity issue and has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats