Junglewise Threat Intelligence

CVE-2026-17985: Google Chrome site isolation bypass in Speech

CVE-2026-17985 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's speech component could allow a malicious website to bypass security boundaries designed to keep data from different sites separate. If a user visits a specially crafted webpage, an attacker might be able to access information from other open websites or browser sessions. This undermines the 'Site Isolation' feature which is a primary defense against cross-site data theft.

Technical details

An insufficient policy enforcement vulnerability exists in the Speech component of Google Chrome. By utilizing a specially crafted HTML page, a remote attacker can bypass Site Isolation, a security feature that ensures pages from different websites are run in separate processes. This flaw allows for potential cross-origin data access. The vulnerability is addressed in Google Chrome version 151.0.7922.72. The issue was assigned a 'Low' severity rating by the Chromium security team.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats