Junglewise Threat Intelligence

CVE-2026-17962: Google Chrome Blink Universal Cross-Site Scripting

CVE-2026-17962 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Blink rendering engine could allow a malicious website to bypass security boundaries and execute unauthorized scripts or display fake content in the context of other websites. This could lead to the theft of sensitive information, such as login credentials or session cookies, from other sites the user has open.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Blink rendering engine of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly isolate script execution environments under certain conditions. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to inject and execute arbitrary scripts or HTML across different origins. This bypasses the Same-Origin Policy (SOP), potentially leading to data exfiltration or unauthorized actions in the context of other web applications. The issue is resolved in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats