Junglewise Threat Intelligence

CVE-2026-17986: Google Chrome Same Origin Policy bypass in Bluetooth

CVE-2026-17986 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's Bluetooth component could allow a remote attacker to bypass the browser's Same Origin Policy. This policy is a fundamental security mechanism that prevents websites from accessing data from other websites. If exploited, an attacker who has already partially compromised the browser's rendering process could potentially access sensitive information or interact with data from other open websites or services.

Technical details

A vulnerability exists in the Bluetooth component of Google Chrome due to insufficient policy enforcement. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by utilizing a specially crafted HTML page. A precondition for this exploit is that the attacker must have already compromised the renderer process. By bypassing SOP, the attacker can potentially access data across different origins, leading to information disclosure. This issue is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats