Junglewise Threat Intelligence

CVE-2026-17845: Google Chrome UXSS in CSS implementation

CVE-2026-17845 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its CSS implementation. This flaw could allow a malicious website to bypass security boundaries and execute unauthorized scripts or HTML in the context of other websites the user is visiting. This type of attack, known as Universal Cross-Site Scripting (UXSS), could lead to the theft of sensitive information, such as login credentials or personal data, from any site currently open in the browser.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's CSS implementation prior to version 151.0.7922.72. The flaw stems from an inappropriate implementation that allows a remote attacker to bypass the Same-Origin Policy (SOP) via a specially crafted HTML page. By enticing a user to visit a malicious site, an attacker can inject and execute arbitrary scripts or HTML across different origins. This vulnerability is tracked as CVE-2026-17845 and was addressed in the Stable Channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats