Junglewise Threat Intelligence

CVE-2026-17851: Google Chrome side-channel information leakage in Autofill

CVE-2026-17851 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Autofill feature could allow a malicious website to steal sensitive information from other websites. This occurs if an attacker has already partially compromised the browser's internal processing systems. Users are advised to update to the latest version of Chrome to prevent potential data leakage.

Technical details

A side-channel information leakage vulnerability (CWE-1300) exists in the Autofill component of Google Chrome. The flaw allows a remote attacker to leak cross-origin data by enticing a user to visit a specially crafted HTML page. A significant precondition for this attack is that the attacker must have already compromised the renderer process. By exploiting this side channel, the attacker can bypass certain cross-origin isolation boundaries. The issue is resolved in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats