Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17957

CVE-2026-17957: Google Chrome CORS Information Disclosure

CVE-2026-17957 is an information disclosure vulnerability in Google Chrome's CORS implementation that enables cross-origin data leakage. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-17957 Overview

CVE-2026-17957 is an inappropriate implementation flaw in the Cross-Origin Resource Sharing (CORS) subsystem of Google Chrome versions prior to 151.0.7922.72. The vulnerability allows a remote attacker who has already compromised the renderer process to leak cross-origin data through a crafted HTML page. Google's Chromium security team rated the underlying issue at Low severity. Exploitation requires prior compromise of the renderer, which limits the practical attack surface but preserves value in multi-stage exploit chains that already achieve code execution in the sandbox.

Critical Impact

Attackers who control a compromised renderer can bypass same-origin protections and exfiltrate data belonging to other web origins loaded in the browser.

Affected Products

  • Google Chrome for Desktop versions prior to 151.0.7922.72
  • Chromium-based browsers incorporating the vulnerable CORS implementation
  • Downstream products embedding pre-patch Chromium builds

Discovery Timeline

  • 2026-07-30 - CVE-2026-17957 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-17957

Vulnerability Analysis

The defect resides in Chrome's CORS enforcement logic, which mediates how a rendering process can request and read resources from origins other than its own. An inappropriate implementation in this pathway permits a renderer that has already been subverted by an attacker to obtain data it should be forbidden from reading under the same-origin policy. The issue is classified as an information disclosure weakness affecting the browser's cross-origin boundary [CWE-346 class]. Because the CORS check is enforced within the renderer's request pipeline rather than solely at the network service, a compromised renderer can influence the outcome and receive responses that violate the origin boundary.

Root Cause

The root cause is an incorrect enforcement path in the CORS implementation shipped in Chrome versions before 151.0.7922.72. The check that should isolate cross-origin responses from the requesting context does not fully constrain a renderer whose integrity has already been broken. This design gap converts a post-compromise scenario into a cross-origin data leak.

Attack Vector

Exploitation is a two-stage process. First, an attacker must compromise the renderer process, typically by chaining a separate memory corruption or logic bug reachable through a malicious web page. Second, the attacker delivers a crafted HTML page that drives the compromised renderer to issue cross-origin requests whose responses are exposed back to attacker-controlled code. The output is disclosure of data such as authenticated content, tokens, or other sensitive material from other origins the victim is browsing.

No verified proof-of-concept code has been published. Technical detail is tracked in the Chromium Issue Tracker Entry and the Google Chrome Desktop Update.

Detection Methods for CVE-2026-17957

Indicators of Compromise

  • Chrome browser processes running versions earlier than 151.0.7922.72 on managed endpoints
  • Renderer processes issuing unexpected sequences of cross-origin fetches following navigation to untrusted pages
  • Outbound requests from browser hosts containing sensitive tokens or session material destined for attacker-controlled domains

Detection Strategies

  • Inventory installed browser versions across the fleet and flag any Chrome or Chromium build older than 151.0.7922.72
  • Correlate browser process telemetry with network egress to identify anomalous cross-origin data flows after renderer exploitation
  • Alert on renderer processes spawning unusual child processes or writing to unexpected locations, which typically precede the CORS abuse stage

Monitoring Recommendations

  • Ingest endpoint browser version data into asset management and vulnerability dashboards
  • Monitor proxy and DNS logs for connections to newly registered or low-reputation domains following user web activity
  • Track Chrome update channel status to confirm managed hosts are receiving stable channel patches promptly

How to Mitigate CVE-2026-17957

Immediate Actions Required

  • Update Google Chrome to version 151.0.7922.72 or later on all Windows, macOS, and Linux desktops
  • Restart Chrome after the update to ensure the patched binary is loaded into all renderer processes
  • Audit Chromium-based applications and embedded browser components for the same underlying version and update them

Patch Information

Google released the fix in the Chrome Stable channel as documented in the Google Chrome Desktop Update. Administrators should deploy 151.0.7922.72 or later through managed update infrastructure and validate rollout across all supported platforms.

Workarounds

  • Enforce automatic Chrome updates through enterprise policy so patched builds reach endpoints without user action
  • Restrict browsing to trusted sites using URL filtering to reduce exposure to malicious pages that stage renderer exploits
  • Enable site isolation and strict cross-origin policies on high-value web applications to limit the value of any leaked data
bash
# Verify installed Chrome version on Linux and macOS endpoints
google-chrome --version

# Windows: query the installed version from the registry
reg query "HKLM\Software\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Force update check on Linux
sudo apt-get update && sudo apt-get install --only-upgrade google-chrome-stable

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.