Junglewise Threat Intelligence

CVE-2026-17982: Google Chrome same origin policy bypass in Cast

CVE-2026-17982 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Cast component could allow a malicious website to bypass security boundaries that normally prevent different sites from accessing each other's data. If a user visits a specially crafted webpage, an attacker could potentially access sensitive information from other open websites or services. This issue is rated as low severity by the developer and has been addressed in the latest browser update.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Cast component of Google Chrome. The flaw allows a remote attacker to bypass the Same-Origin Policy (SOP) by enticing a user to visit a maliciously crafted HTML page. Successful exploitation could lead to unauthorized access to data across origin boundaries. The vulnerability is fixed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux. Google classifies this as a Low severity issue.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats