CVE-2026-17907
Description
A flaw was found in Google Chrome's Network component. A remote attacker could exploit this side-channel information leakage vulnerability by enticing a user to visit a specially crafted HTML page. This could allow the attacker to leak sensitive cross-origin data.
Statement
This Moderate-severity flaw in the Chromium browser's network component allows a remote attacker to leak cross-origin data. Exploitation requires a user to visit a specially crafted HTML page, limiting the impact to information disclosure rather than arbitrary code execution. Red Hat users running Chromium are affected if they browse untrusted web content.
Understanding the Weakness (CWE)
Access Control,Other
Technical Impact: Gain Privileges or Assume Identity; Varies by Context
An attacker can access any functionality that is inadvertently accessible to the source.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.