Junglewise Threat Intelligence

CVE-2026-17904: Google Chrome for Android cross-origin data leak in NFC

CVE-2026-17904 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for Android could allow a malicious website to access data from other websites you have open. This occurs due to a flaw in how the browser handles Near Field Communication (NFC) policies. While the risk is rated as low, an attacker could potentially leak sensitive information if a user visits a specially crafted web page.

Technical details

An insufficient policy enforcement vulnerability exists in the NFC component of Google Chrome for Android. The flaw allows a remote attacker to bypass cross-origin restrictions and leak data from different origins by enticing a user to visit a malicious HTML page. This is classified as a cross-origin data leak. The vulnerability was addressed in version 151.0.7922.72. Access to specific bug details remains restricted by the Chromium team to allow users time to update.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats