Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17662

CVE-2026-17662: Google Chrome Information Disclosure Flaw

CVE-2026-17662 is an information disclosure vulnerability in Google Chrome's Prefetch feature that enables attackers to leak cross-origin data. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-17662 Overview

CVE-2026-17662 is an insufficient policy enforcement vulnerability in the Prefetch component of Google Chrome prior to version 151.0.7922.72. A remote attacker can leak cross-origin data by serving a crafted HTML page to a targeted user. Google classifies the Chromium security severity as High. The flaw impacts the browser's enforcement of origin boundaries during resource prefetching, allowing attacker-controlled pages to observe data that should be isolated by the same-origin policy.

Critical Impact

Cross-origin data leakage via crafted HTML delivered through standard web navigation, requiring no authentication and no user interaction beyond visiting a malicious page.

Affected Products

  • Google Chrome Desktop versions prior to 151.0.7922.72
  • Chromium-based browsers incorporating the affected Prefetch implementation
  • All supported desktop platforms (Windows, macOS, Linux) running vulnerable Chrome builds

Discovery Timeline

  • 2026-07-30 - CVE-2026-17662 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-17662

Vulnerability Analysis

The vulnerability resides in Chrome's Prefetch subsystem, which speculatively fetches resources a page indicates it may need. Prefetch operations must honor cross-origin policies to prevent one site from observing responses intended for another origin. In affected versions, policy enforcement is incomplete, allowing an attacker-controlled page to trigger prefetch behavior that exposes cross-origin response data. The result is an information disclosure primitive that undermines web origin isolation.

Exploitation is remote and requires only that a victim load a crafted HTML page. The attacker does not need credentials, elevated privileges, or additional user interaction beyond page navigation. EPSS currently estimates a low near-term exploitation likelihood, but the class of bug — origin boundary bypass in a widely deployed browser — warrants prompt patching.

Root Cause

The root cause is insufficient policy enforcement within the Prefetch code path. Origin, credentials mode, or partitioning checks that should gate cross-origin prefetch handling are either missing or applied inconsistently. As a result, response state that should remain isolated to its originating security context becomes observable to an attacker's page. See the Chromium Issue Tracker entry for upstream references.

Attack Vector

An attacker hosts a crafted HTML page and lures a victim to visit it through phishing, malvertising, or a compromised site. The page issues prefetch requests structured to exercise the flawed enforcement path. The attacker then infers or reads cross-origin response data returned to the browser, breaking the same-origin policy for the targeted resources. No verified public proof-of-concept has been released. Refer to the Google Chrome Desktop Update advisory for vendor-confirmed details.

Detection Methods for CVE-2026-17662

Indicators of Compromise

  • Chrome browser processes running versions earlier than 151.0.7922.72 after the patch release window
  • Outbound HTTP requests containing prefetch hints (<link rel="prefetch">, Speculation-Rules headers) to attacker-controlled domains
  • User navigation to newly registered or low-reputation domains delivering HTML with unusual prefetch directives

Detection Strategies

  • Inventory installed browser versions across managed endpoints and flag Chrome builds below 151.0.7922.72
  • Inspect proxy and DNS telemetry for prefetch-heavy pages loaded from untrusted origins targeting sensitive internal domains
  • Correlate browser process telemetry with network egress to detect anomalous cross-origin fetch patterns following visits to unfamiliar sites

Monitoring Recommendations

  • Enable browser version reporting through enterprise management (Chrome Browser Cloud Management or equivalent) and alert on non-compliant clients
  • Monitor web gateway logs for HTML content referencing prefetch or speculation rules toward external hosts
  • Track user reports of unexpected authentication prompts or session anomalies that could indicate cross-origin data exposure

How to Mitigate CVE-2026-17662

Immediate Actions Required

  • Update all Google Chrome installations to version 151.0.7922.72 or later on Windows, macOS, and Linux
  • Push the update via enterprise browser management to ensure remediation across unmanaged and remote endpoints
  • Restart Chrome processes after update to ensure the patched binary is loaded into memory

Patch Information

Google released the fix in the Chrome Stable Channel update announced on the Chrome Releases blog. The patched version is 151.0.7922.72. Chromium-derived browsers (Edge, Brave, Opera, Vivaldi) should be updated once their vendors ship a corresponding release incorporating the upstream fix.

Workarounds

  • If patching is delayed, restrict browsing to trusted sites via enterprise URL allowlists to reduce exposure to crafted HTML pages
  • Disable network prediction and prefetch features through the NetworkPredictionOptions Chrome policy where operationally acceptable
  • Enforce web content filtering at the proxy to block newly registered and low-reputation domains that commonly host exploit landing pages
bash
# Configuration example: disable network prediction via Chrome enterprise policy (Linux managed policy JSON)
cat > /etc/opt/chrome/policies/managed/disable_prefetch.json <<'EOF'
{
  "NetworkPredictionOptions": 2
}
EOF

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.