
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2317 is an "Inappropriate implementation in Animation" vulnerability in Google Chrome that allows a remote attacker to leak cross-origin data via a crafted HTML page. It affects all versions of Google Chrome prior to 145.0.7632.45 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Brendan Draper on 2025-11-28 and publicly disclosed on February 10–11, 2026, when Google released Chrome 145 to the stable channel. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, Microsoft MSRC).
The root cause is an inappropriate implementation in Chrome's Animation subsystem (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). By crafting a malicious HTML page that exploits the flawed animation handling, a remote attacker can cause the browser to inadvertently expose data from cross-origin resources, violating the Same-Origin Policy. Exploitation requires no special privileges and has low attack complexity, but does require user interaction — specifically, a victim must visit the attacker-controlled page. No detailed technical write-up or public proof-of-concept code has been published as of the time of this report (Chrome Releases, Feedly).
Successful exploitation results in a high confidentiality impact, as sensitive cross-origin data can be leaked to the attacker. There is no integrity or availability impact — the vulnerability is limited to information disclosure. The attack surface is broad given Chrome's widespread deployment, and leaked cross-origin data could include authentication tokens, session identifiers, or other sensitive page content from sites visited by the victim (Chrome Releases, Feedly).
Google has addressed this vulnerability in Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac), released on February 10, 2026. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referencing this CVE. Organizations should prioritize updating all endpoints running Chrome versions prior to 145.0.7632.45. No configuration-based workaround is available; upgrading to the patched version is the only remediation (Chrome Releases, Microsoft MSRC).
The Chrome 145 release was covered by several security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress, which highlighted the broader set of 11 security fixes in the update, including three high-severity flaws. Community discussion on Reddit's r/pwnhub noted the fixes. Palo Alto Networks issued a security advisory (PAN-SA-2026-0003) covering the Chromium monthly vulnerability update for March 2026, which included this CVE. No notable individual researcher commentary specific to CVE-2026-2317 has been identified beyond the initial bug report by Brendan Draper (Chrome Releases, Palo Alto Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."