Junglewise Threat Intelligence

CVE-2026-17933: Google Chrome cross-origin data leak in DOMStorage

CVE-2026-17933 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability was identified in Google Chrome's DOMStorage component, which handles how websites store data locally in your browser. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to access data belonging to other websites. This could lead to the unauthorized disclosure of sensitive information across different web domains.

Technical details

An inappropriate implementation vulnerability exists in the DOMStorage component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by enticing a user to visit a malicious HTML page. Successful exploitation enables the attacker to leak data from different origins, violating the Same-Origin Policy (SOP). The issue is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats