Junglewise Threat Intelligence

CVE-2026-17905: Google Chrome cross-origin data leak in SurfaceCapture

CVE-2026-17905 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's SurfaceCapture component could allow a malicious website to access data from other websites you have open. This bypasses standard browser security boundaries that normally keep data from different sites isolated. While rated as low severity, it could lead to the unauthorized disclosure of information if a user visits a specially crafted webpage.

Technical details

An inappropriate implementation vulnerability exists in the SurfaceCapture component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin resource sharing (CORS) or similar isolation policies to leak data from different origins. The vulnerability is present in versions prior to 151.0.7922.72 and has been assigned a 'Low' severity rating by the Chromium project.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released the stable channel update fixing the issue.
  • 2026-07-30: disclosed: NVD published the CVE record.

References

Related threats