CVE-2026-17667
published 2026-07-30CVE-2026-17667: Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.40%
32.8th percentile
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 151.0.7922.72 | 151.0.7922.72 | |
| chrome | >= 151.0.7922.72 < 151.0.7922.72 | 151.0.7922.72 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 150.0.7871.186 ANGLE uninitialized pointer
vuldb·2026-07-30
CVE-2026-17667 [LOW] Google Chrome up to 150.0.7871.186 ANGLE uninitialized pointer
A vulnerability, which was classified as problematic, has been found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component ANGLE. The manipulation leads to uninitialized pointer.
This vulnerability is traded as CVE-2026-17667. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ghsa_unreviewed·2026-07-30
CVE-2026-17667 [MEDIUM] CWE-457 Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Red Hat
chromium-browser: chromium-browser: Uninitialized Use in ANGLE
vendor_redhat·2026-07-30·CVSS 6.5
CVE-2026-17667 [MEDIUM] CWE-824 chromium-browser: chromium-browser: Uninitialized Use in ANGLE
chromium-browser: chromium-browser: Uninitialized Use in ANGLE
An uninitialized use flaw was found in the ANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513043537
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-17665
vendor_chrome·2026-07-29
CVE-2026-17665 [HIGH] Stable Channel Update for Desktop: CVE-2026-17665
Stable Channel Update for Desktop
CVE-2026-17665: Use after free in V8. Reported by Google on 2026-05-08 [N/A][ 511761758 ] High CVE-2026-17666: Cryptographic Flaw in Enterprise
Reported by Google on 2026-05-10 [N/A][ 513043537 ] High CVE-2026-17667: Uninitialized Use in ANGLE
Severity: high
No detection rules found.
No public exploits indexed.
2026-07-30
Published