Junglewise Threat Intelligence

CVE-2026-17885: Google Chrome cross-origin data leak in Paint

CVE-2026-17885 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its 'Paint' component could allow a malicious website to access data from other websites you have open or are logged into. This could lead to the unauthorized disclosure of sensitive information across different web domains.

Technical details

An inappropriate implementation vulnerability exists in the Paint component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin isolation and leak data from different origins. The vulnerability is fixed in version 151.0.7922.72 and later. Chromium developers have assigned this a severity of Medium.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats