Junglewise Threat Intelligence

CVE-2026-17850: Google Chrome Same Origin Policy bypass in Permissions

CVE-2026-17850 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its permissions handling system. This vulnerability could allow a malicious website to bypass the browser's security boundaries, potentially accessing data from other websites you have open. Users are advised to update to the latest version of Chrome to protect their information.

Technical details

A vulnerability in the Permissions component of Google Chrome was identified as an inappropriate implementation that fails to strictly enforce origin boundaries. By enticing a user to visit a specially crafted HTML page, a remote attacker could exploit this flaw to bypass the Same Origin Policy (SOP). This could lead to unauthorized access to sensitive data across different web origins. The issue is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. The vulnerability is categorized by Chromium developers as Medium severity.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats