Junglewise Threat Intelligence

CVE-2026-17910: Google Chrome for Android cross-origin data leak in NFC

CVE-2026-17910 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A security flaw in the browser's Near Field Communication (NFC) handling could allow a malicious website to access data from other websites that the user has open. This could lead to the unauthorized exposure of sensitive user information or browsing data.

Technical details

An information disclosure vulnerability exists in Google Chrome for Android due to insufficient policy enforcement within the NFC component. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak data from other origins. This issue was addressed in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats