Junglewise Threat Intelligence

CVE-2026-17954: Google Chrome policy bypass in MHTML

CVE-2026-17954 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's MHTML handling could allow a malicious website to access data from other websites you have open. MHTML is a format used to save entire web pages into a single file. If a user visits a specially crafted page, an attacker could bypass security boundaries to leak sensitive information across different web origins.

Technical details

A policy bypass vulnerability exists in the MHTML component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections by enticing a user to open a specially crafted MHTML file or page. Successful exploitation enables the attacker to leak sensitive data from different origins (cross-origin data). The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Google classifies this as a Low severity issue.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats