CVE-2026-17743 Overview
CVE-2026-17743 is a same-origin policy bypass vulnerability in the ControlledFrame component of Google Chrome prior to version 151.0.7922.72. The flaw stems from insufficient policy enforcement, allowing a remote attacker to bypass same-origin policy through a crafted HTML page. Chromium rates the security severity as Medium.
Same-origin policy is a foundational browser security control. It prevents scripts loaded from one origin from accessing data on another. A bypass allows cross-origin data access that the browser would normally block.
Critical Impact
A remote attacker can bypass same-origin policy via a crafted HTML page, enabling unauthorized cross-origin data access in affected Chrome installations.
Affected Products
- Google Chrome versions prior to 151.0.7922.72
- Chromium-based browsers embedding the vulnerable ControlledFrame implementation
- Desktop Chrome Stable channel builds released before the July 2026 update
Discovery Timeline
- 2026-07-30 - CVE-2026-17743 published to NVD
- 2026-07-30 - Last updated in NVD database
Technical Details for CVE-2026-17743
Vulnerability Analysis
The vulnerability resides in ControlledFrame, a Chrome feature that embeds and controls guest web content within isolated web applications. Insufficient policy enforcement in this component permits a crafted HTML page to circumvent the browser's same-origin policy.
Same-origin policy restricts how a document or script loaded from one origin can interact with resources from another origin. When enforcement gaps exist in embedding primitives like ControlledFrame, an attacker-controlled page can read or manipulate cross-origin content that should be inaccessible.
Successful exploitation can lead to disclosure of cross-origin data, session information, or authenticated responses returned to the victim's browser. The attack requires only that a user visit or load a crafted HTML page.
Root Cause
The root cause is missing or incomplete origin-boundary checks within the ControlledFrame policy enforcement logic. The component fails to consistently apply same-origin restrictions to certain operations against embedded or referenced resources. Details are tracked in the Chromium Issue Tracker Entry.
Attack Vector
The attack vector is remote and network-based. An attacker hosts or delivers a crafted HTML page and lures a victim to load it in a vulnerable Chrome build. Once loaded, the page abuses ControlledFrame behavior to reach data across origin boundaries without user interaction beyond page navigation.
No verified public proof-of-concept code is available at the time of publication. Refer to the Google Chrome Stable Update advisory for vendor context.
Detection Methods for CVE-2026-17743
Indicators of Compromise
- Chrome browser processes running versions below 151.0.7922.72 in enterprise inventory
- Outbound requests to untrusted domains loading pages that instantiate ControlledFrame elements
- Unusual cross-origin data reads in browser telemetry originating from embedded frames
Detection Strategies
- Inventory Chrome installations and flag any build older than 151.0.7922.72 as vulnerable
- Monitor web proxy and DNS logs for user visits to newly registered or low-reputation domains serving HTML with ControlledFrame usage
- Correlate browser crash reports and renderer anomalies with visits to untrusted pages
Monitoring Recommendations
- Ingest Chrome version telemetry into centralized logging to track patch coverage across endpoints
- Alert on browser installations that fall behind the current Stable channel release for more than one patch cycle
- Review enterprise browser policy reports for unexpected use of Isolated Web Apps or ControlledFrame APIs
How to Mitigate CVE-2026-17743
Immediate Actions Required
- Update Google Chrome to version 151.0.7922.72 or later on all managed endpoints
- Force-restart Chrome processes after deployment to ensure the patched binary is loaded
- Verify Chromium-based browsers and embedded frameworks have absorbed the upstream fix
Patch Information
Google released the fix in the Chrome Stable channel update documented in the Google Chrome Stable Update advisory. Upgrade to Chrome 151.0.7922.72 or later. Chromium-based browsers should apply the corresponding merged upstream commit.
Workarounds
- Restrict user navigation to untrusted sites via enterprise web filtering while patches are staged
- Disable or block use of ControlledFrame and Isolated Web Apps through Chrome enterprise policy where feasible
- Enforce automatic Chrome updates through group policy or mobile device management to minimize exposure windows
# Verify installed Chrome version on Linux/macOS endpoints
google-chrome --version
# Windows: query installed version via registry
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

