Junglewise Threat Intelligence

CVE-2026-17925: Google Chrome Cast same origin policy bypass on Android

CVE-2026-17925 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Cast component of Google Chrome on Android could allow a malicious website to bypass security boundaries. This could lead to the unauthorized access of data from other websites or services that the user is currently logged into. Users are advised to update their browser to the latest version to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists in the Cast component of Google Chrome for Android. By convincing a user to visit a specially crafted HTML page, a remote attacker can bypass the Same-Origin Policy (SOP). This bypass allows the attacker to potentially access sensitive data or interact with web content across different origins. The vulnerability is addressed in version 151.0.7922.72. Google classifies this as a Low severity issue.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: patched
  • 2026-07-30: advisory

References

Related threats