Junglewise Threat Intelligence

CVE-2026-17980: Google Chrome for Android cross-origin data leak in UI

CVE-2026-17980 · Severity: info · CVSS 3.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to trick users into revealing private information from other websites. By convincing a user to perform specific touch gestures or interactions on a specially crafted page, an attacker can bypass security boundaries that normally keep data from different sites separate. This could lead to the unauthorized disclosure of sensitive user data.

Technical details

An inappropriate implementation vulnerability exists in the UI component of Google Chrome for Android prior to version 151.0.7922.72. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. Exploitation requires the attacker to host a malicious HTML page and successfully trick a user into performing specific UI gestures. This interaction facilitates the side-channel leakage of information from other origins. Google has addressed this issue in the stable channel update 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats