Junglewise Threat Intelligence

CVE-2026-17897: Google Chrome cross-origin data leak in ORB

CVE-2026-17897 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Opaque Response Blocking (ORB) mechanism, which is designed to protect sensitive data from being accessed by unauthorized websites. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially allowing the attacker to steal private information from other websites the user is logged into. This could lead to the exposure of sensitive customer data or personal information.

Technical details

A cross-origin data leak vulnerability exists in the Opaque Response Blocking (ORB) component of Google Chrome. The flaw stems from an inappropriate implementation of ORB logic, which is intended to prevent cross-site script-based Deanonymization and data theft. By enticing a user to visit a malicious website, a remote attacker can bypass these protections to read sensitive data from a different origin. This vulnerability is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats