Junglewise Threat Intelligence

CVE-2026-17854: Google Chrome Same Origin Policy bypass in WebMCP

CVE-2026-17854 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebMCP component could allow a malicious website to bypass the browser's Same Origin Policy. This security boundary is designed to prevent websites from accessing data from other sites; if bypassed, an attacker could potentially steal sensitive information or perform unauthorized actions on behalf of a user. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An insufficient policy enforcement vulnerability exists in the WebMCP component of Google Chrome. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit this flaw to bypass the Same Origin Policy (SOP). This bypass could allow the attacker to access sensitive data or interact with web content from other origins that should be restricted. The vulnerability is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released
  • 2026-07-30: disclosed: NVD publication date

References

Related threats