Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17783

CVE-2026-17783: Google Chrome Information Disclosure Flaw

CVE-2026-17783 is an information disclosure vulnerability in Google Chrome's Loader component that enables attackers to leak cross-origin data via malicious HTML pages. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-17783 Overview

CVE-2026-17783 is an information disclosure vulnerability in the Loader component of Google Chrome versions prior to 151.0.7922.72. A remote attacker can leak cross-origin data by convincing a user to load a crafted HTML page. Google's Chromium security team rated the severity as Medium. The flaw violates the browser's same-origin policy, which is designed to prevent one origin from reading resources served by another. Successful exploitation gives an attacker access to data that should be isolated between web origins, including potentially sensitive session or content information.

Critical Impact

A crafted web page can bypass same-origin protections in the Chrome Loader and read data belonging to other web origins, exposing user information across sites.

Affected Products

  • Google Chrome for Desktop prior to 151.0.7922.72
  • Chromium-based browsers incorporating the vulnerable Loader implementation
  • Downstream distributions that had not yet integrated the Chromium 151 fix

Discovery Timeline

  • 2026-07-30 - CVE-2026-17783 published to NVD
  • 2026-07-30 - Last updated in NVD database

Additional context is available in the Google Chrome Desktop Update and the Chromium Issue Tracker Entry.

Technical Details for CVE-2026-17783

Vulnerability Analysis

The vulnerability resides in Chrome's Loader, the subsystem responsible for fetching resources and enforcing origin boundaries on responses. An inappropriate implementation in this component allows a crafted HTML page to obtain data that should be restricted by the same-origin policy. The issue falls into the Information Disclosure category and specifically enables cross-origin data leakage.

Because the Loader mediates requests for scripts, images, stylesheets, and other subresources, a defect in its enforcement logic can expose response contents or metadata to script running in an unrelated origin. Attackers can leverage such leaks to read authenticated content, harvest tokens embedded in responses, or fingerprint a user's activity on third-party sites.

Root Cause

Google describes the defect as an inappropriate implementation in the Loader. The specific code path has not been publicly disclosed, consistent with Chromium's practice of restricting issue tracker access until a majority of users have updated. Details remain embargoed in the Chromium Issue Tracker Entry.

Attack Vector

Exploitation is remote and requires user interaction. The victim must visit or be redirected to an attacker-controlled page. The malicious page issues resource requests structured to trigger the Loader's incorrect behavior, then reads response data that the same-origin policy should have blocked. No authentication is required against the attacker's site, and no elevated browser privileges are needed on the victim's machine.

No public proof-of-concept exploit code is available for CVE-2026-17783. The vulnerability mechanism is described in vendor advisories rather than in released technical write-ups.

Detection Methods for CVE-2026-17783

Indicators of Compromise

  • Chrome browser processes reporting a version string below 151.0.7922.72 in enterprise inventory data
  • Outbound traffic to unfamiliar domains immediately after a user visits a suspicious link, followed by requests to third-party authenticated services
  • Web proxy logs showing HTML pages that trigger unusual patterns of cross-origin subresource requests

Detection Strategies

  • Inventory installed Chrome versions across managed endpoints and flag any build older than 151.0.7922.72
  • Correlate browser telemetry with proxy or DNS logs to identify sessions where users loaded pages that immediately fetched cross-origin resources with unusual response handling
  • Monitor for phishing or malvertising campaigns delivering links to unfamiliar domains, which is the primary delivery method for browser information-disclosure exploits

Monitoring Recommendations

  • Enable Chrome enterprise reporting to centralize version data and update status
  • Retain web proxy and DNS logs long enough to reconstruct browsing sessions during incident response
  • Alert on execution of Chrome binaries whose reported version is below the fixed release for at least 30 days after patch availability

How to Mitigate CVE-2026-17783

Immediate Actions Required

  • Update Google Chrome to version 151.0.7922.72 or later on all managed endpoints
  • Force-restart Chrome sessions after deployment so the patched binary is actually loaded into memory
  • Verify that Chromium-based browsers in the environment, including embedded WebView components, have integrated the corresponding upstream fix
  • Communicate the update requirement to users of unmanaged or BYOD devices that access corporate web applications

Patch Information

Google addressed CVE-2026-17783 in Chrome Stable channel version 151.0.7922.72 for Desktop. Distribution details are documented in the Google Chrome Desktop Update announcement. Administrators should confirm rollout status via Chrome's built-in update mechanism or enterprise management tooling.

Workarounds

  • No vendor-supplied workaround exists; patching is the supported remediation path
  • Restrict user access to untrusted sites via web filtering until the update is confirmed deployed
  • Enforce Chrome auto-update policies through Group Policy, Jamf, or equivalent management tools to prevent version drift
bash
# Verify installed Chrome version on Windows endpoints
reg query "HKLM\Software\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Verify installed Chrome version on macOS endpoints
defaults read /Applications/Google\ Chrome.app/Contents/Info CFBundleShortVersionString

# Verify installed Chrome version on Linux endpoints
google-chrome --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.