Junglewise Threat Intelligence

CVE-2026-17883: Google Chrome Same Origin Policy bypass in Headless mode

CVE-2026-17883 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability was identified in Google Chrome's Headless mode, a version of the browser used primarily by developers for automated testing and server-side tasks. A remote attacker could use a specially crafted website to bypass the browser's Same Origin Policy, which is a fundamental security mechanism designed to prevent websites from accessing each other's data. If exploited, this could allow an attacker to potentially access sensitive information from other websites that the user or automated process has open.

Technical details

A Same Origin Policy (SOP) bypass vulnerability exists in Google Chrome's Headless implementation. The flaw stems from an inappropriate implementation within the Headless component, which fails to strictly enforce origin boundaries when processing certain HTML content. A remote attacker can exploit this by enticing a user (or an automated headless process) to load a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass SOP protections, potentially leading to unauthorized cross-origin data access. The vulnerability is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats