Junglewise Threat Intelligence

CVE-2026-18004: Google Chrome insufficient policy enforcement in Speech

CVE-2026-18004 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's speech component could allow a remote attacker to access sensitive data from other websites. This issue requires the attacker to have already partially compromised the browser's rendering process. If exploited, it could lead to the unauthorized disclosure of user information across different web domains.

Technical details

This vulnerability is classified as insufficient policy enforcement within the Speech component of Google Chrome. The flaw resides in how the browser handles cross-origin data boundaries when speech features are utilized. An attacker who has already achieved code execution within a compromised renderer process can bypass these boundaries to leak data from other origins using a specially crafted HTML page. This is a post-compromise information leak, meaning the attacker must first exploit a separate vulnerability to compromise the renderer. The issue is addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats