Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its CSS implementation. This flaw could allow a malicious website to bypass security boundaries and execute unauthorized scripts or HTML in the context of other websites the user is visiting. This type of attack, known as Universal Cross-Site Scripting (UXSS), could lead to the theft of sensitive information, such as login credentials or personal data, from any site currently open in the browser.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's CSS implementation prior to version 151.0.7922.72. The flaw stems from an inappropriate implementation that allows a remote attacker to bypass the Same-Origin Policy (SOP) via a specially crafted HTML page. By enticing a user to visit a malicious site, an attacker can inject and execute arbitrary scripts or HTML across different origins. This vulnerability is tracked as CVE-2026-17845 and was addressed in the Stable Channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed