Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17907

CVE-2026-17907: Google Chrome Information Disclosure Flaw

CVE-2026-17907 is a side-channel information leakage vulnerability in Google Chrome that enables remote attackers to leak cross-origin data via crafted HTML pages. This article covers technical details, affected versions, and patches.

Published:

CVE-2026-17907 Overview

CVE-2026-17907 is a side-channel information leakage vulnerability in the Network component of Google Chrome. The flaw affects Chrome versions prior to 151.0.7922.72. A remote attacker can leak cross-origin data by convincing a user to visit a crafted HTML page. Google's Chromium security team rated the severity as Low. The weakness is classified under CWE-1300: Improper Protection of Physical Side Channels, covering side-channel information disclosure conditions.

Critical Impact

Remote attackers can extract cross-origin data from other web origins by luring a target to a malicious page, undermining the browser's same-origin isolation guarantees.

Affected Products

  • Google Chrome Desktop versions prior to 151.0.7922.72
  • Chromium-based browsers that consume the same Network stack code path
  • Chrome Stable channel deployments not yet updated

Discovery Timeline

  • 2026-07-30 - CVE-2026-17907 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-17907

Vulnerability Analysis

The vulnerability resides in Chrome's Network component. It permits observation of characteristics tied to cross-origin resources through a side channel rather than direct access. An attacker hosts a crafted HTML page that triggers network operations against a victim's authenticated origins. The attacker then infers cross-origin content by measuring observable side effects of those operations. This class of flaw bypasses the same-origin policy without reading responses directly. Google labeled the Chromium security severity as Low, which reflects the constrained data types typically obtainable through such channels. See the Chromium Issue Tracker Entry and the Chrome Desktop Update Blog for vendor-side context.

Root Cause

The root cause is improper protection of a side channel in Chrome's Network handling, matching [CWE-1300]. Observable behavior tied to cross-origin resources leaks information that the browser's isolation model is intended to conceal.

Attack Vector

Exploitation requires a user to load attacker-controlled HTML in a vulnerable Chrome build. The page issues network requests and measures side-channel signals to infer cross-origin data. No authentication to the attacker's site is required, and no additional privileges are needed on the victim host.

// No verified proof-of-concept code is public for CVE-2026-17907.
// Refer to the Chromium Issue Tracker entry (issue 497837927)
// once access restrictions are lifted for technical specifics.

Detection Methods for CVE-2026-17907

Indicators of Compromise

  • Chrome browser process versions below 151.0.7922.72 observed on managed endpoints
  • Outbound connections from browsers to unfamiliar domains that immediately serve HTML issuing repeated cross-origin subresource requests
  • Unusual volumes of timing-sensitive fetch or resource-load activity originating from a single tab

Detection Strategies

  • Inventory installed Chrome versions across the fleet and flag any build older than 151.0.7922.72
  • Correlate web proxy logs for pages that trigger high-frequency cross-origin requests to sensitive internal or SaaS origins
  • Alert on browser telemetry that shows scripted access to authenticated third-party origins from newly visited domains

Monitoring Recommendations

  • Track Chrome auto-update status through endpoint management tooling to confirm patch adoption
  • Monitor DNS and proxy logs for known malicious or newly registered domains serving crafted HTML
  • Review browser extension and enterprise policy telemetry for tampering that could disable auto-updates

How to Mitigate CVE-2026-17907

Immediate Actions Required

  • Update Google Chrome to version 151.0.7922.72 or later on all Windows, macOS, and Linux endpoints
  • Restart browser sessions after update deployment so patched binaries are loaded into memory
  • Verify enterprise update channels and group policies are not deferring the Stable channel rollout

Patch Information

Google addressed the issue in the Chrome Stable channel release documented in the Chrome Desktop Update Blog. Fixed version: 151.0.7922.72. Chromium-based browser vendors should pick up the corresponding upstream fix in their next release.

Workarounds

  • Restrict browsing to trusted sites through enterprise web filtering until patches are deployed
  • Enforce site isolation and cross-origin policy protections through Chrome enterprise policy where available
  • Encourage users to avoid untrusted links and to use separate browser profiles for sensitive workflows
bash
# Verify installed Chrome version on Linux endpoints
google-chrome --version

# Verify installed Chrome version on macOS
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --version

# Windows (PowerShell) - query installed Chrome version
(Get-Item "C:\Program Files\Google\Chrome\Application\chrome.exe").VersionInfo.ProductVersion

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.