CVE-2026-17698
7.5Google · Chrome
Google Chrome on Android contains a vulnerability where insufficient UI input validation allows a local attacker to leak sensitive cross-origin data via a crafted HTML page.
Executive summary
A high-severity input validation vulnerability in Google Chrome for Android exposes users to unauthorized cross-origin data leakage.
Vulnerability
This vulnerability involves insufficient validation of untrusted input within the browser UI. An unauthenticated attacker can exploit this flaw by enticing a user to navigate to a crafted HTML page, resulting in the unauthorized disclosure of cross-origin data.
Business impact
The ability to leak cross-origin data poses a significant risk to user privacy and organizational data security. If exploited, an attacker could potentially access sensitive information stored in other origins, such as authentication tokens or personal user data, leading to account compromise or further unauthorized access. The CVSS score of 7.5 reflects this high risk, particularly given the potential for broad impact across the Android user base.
Remediation
Immediate Action: Update Google Chrome on all Android devices to version 151.0.7922.72 or later immediately.
Proactive Monitoring: Monitor device logs and browser security alerts for suspicious navigation patterns or unexpected cross-origin requests.
Compensating Controls: While browser-level patches are primary, ensure that mobile device management (MDM) policies enforce regular application updates to minimize the window of exposure for such vulnerabilities.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a significant security risk for mobile users, as it allows for the silent exfiltration of cross-origin data. Security administrators must prioritize the deployment of the latest Chrome browser updates to all Android endpoints to ensure the vulnerability is remediated. Failure to apply this update leaves users susceptible to data theft through malicious web content.