Junglewise Threat Intelligence

CVE-2026-17984: Google Chrome for Android cross-origin data leak in Browser

CVE-2026-17984 · Severity: info · CVSS 2 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android contains a security flaw that could allow a local attacker to access data from other websites. This occurs when a user interacts with a specially crafted web page, potentially leading to the exposure of sensitive information across different browsing sessions. Users should update their Chrome browser on Android to the latest version to mitigate this risk.

Technical details

An inappropriate implementation in the Browser component of Google Chrome for Android allowed for cross-origin data leakage. A local attacker could exploit this by enticing a user to visit or interact with a specially crafted HTML page. This vulnerability bypasses certain Same-Origin Policy (SOP) protections, enabling the unauthorized access of data belonging to other origins. The issue is addressed in version 151.0.7922.72. Chromium has assigned this a security severity of Low.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released the stable channel update for Chrome.
  • 2026-07-30: disclosed: NVD published the CVE record.

References

Related threats