Junglewise Threat Intelligence

CVE-2026-17909: Google Chrome improper input validation in Isolated Web Apps

CVE-2026-17909 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Isolated Web Apps feature contained a vulnerability that could allow a remote attacker to access data from other websites. Isolated Web Apps are designed to provide a more secure environment for web applications, but this flaw could lead to the unauthorized leakage of sensitive information through malicious network traffic. Users should update to the latest version of Chrome to ensure their data remains protected.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Isolated Web Apps component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be exploited by a remote attacker to leak cross-origin data. By utilizing malicious network traffic, an attacker can bypass intended isolation boundaries to access information from different origins. This vulnerability is rated as Low severity by Chromium and is addressed in version 151.0.7922.72. No user interaction or specific authentication is explicitly required beyond the processing of the malicious traffic.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released the stable channel update fixing the issue.
  • 2026-07-30: disclosed: NVD published the CVE record.

References

Related threats