CVE-2026-17668
published 2026-07-30CVE-2026-17668: Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.40%
32.8th percentile
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 151.0.7922.72 | 151.0.7922.72 | |
| chrome | >= 151.0.7922.72 < 151.0.7922.72 | 151.0.7922.72 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ghsa_unreviewed·2026-07-30
CVE-2026-17668 [MEDIUM] CWE-457 Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
VulDB
Google Chrome up to 150.0.7871.186 ANGLE uninitialized pointer
vuldb·2026-07-30
CVE-2026-17668 [LOW] Google Chrome up to 150.0.7871.186 ANGLE uninitialized pointer
A vulnerability, which was classified as problematic, was found in Google Chrome. Affected by this issue is some unknown functionality of the component ANGLE. The manipulation results in uninitialized pointer.
This vulnerability is known as CVE-2026-17668. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
Red Hat
chromium-browser: chromium-browser: Uninitialized Use in ANGLE
vendor_redhat·2026-07-30·CVSS 6.5
CVE-2026-17668 [MEDIUM] CWE-824 chromium-browser: chromium-browser: Uninitialized Use in ANGLE
chromium-browser: chromium-browser: Uninitialized Use in ANGLE
An uninitialized use flaw was found in the ANGLE component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513134019
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-17668
vendor_chrome·2026-07-29
CVE-2026-17668 [HIGH] Stable Channel Update for Desktop: CVE-2026-17668
Stable Channel Update for Desktop
CVE-2026-17668: Uninitialized Use in ANGLE. Reported by Google on 2026-05-14 [N/A][ 513142464 ] High CVE-2026-17669: Inappropriate implementation in Chrome for iOS
Reported by Google on 2026-05-14 [N/A][ 513228974 ] High CVE-2026-17670: Use after free in Views
Severity: high
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-17668 chromium-browser: chromium-browser: Uninitialized Use in ANGLE
bugzilla·2026-07-30·CVSS 6.5
CVE-2026-17668 [MEDIUM] CVE-2026-17668 chromium-browser: chromium-browser: Uninitialized Use in ANGLE
CVE-2026-17668 chromium-browser: chromium-browser: Uninitialized Use in ANGLE
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Bugzilla
CVE-2026-40975 Spring Boot: Spring Boot: Weak pseudo-random number generation can lead to information disclosure.
bugzilla·2026-04-28·CVSS 7.5
CVE-2026-40975 [HIGH] CVE-2026-40975 Spring Boot: Spring Boot: Weak pseudo-random number generation can lead to information disclosure.
CVE-2026-40975 Spring Boot: Spring Boot: Weak pseudo-random number generation can lead to information disclosure.
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.
Discussion:
This issue has been addressed in the following products:
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
Via RHSA-2026:17668 https://access.redhat.
Bugzilla
CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
bugzilla·2026-03-19·CVSS 8.2
CVE-2026-22731 [HIGH] CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
CVE-2026-22731 Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15.
This CVE is similar but not equivalent to CVE-2026-22733, as the conditions for exploit and vulnerable versions are different.
Discussion:
This issue has been addressed in the following products:
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
Via RHSA-2026:17668 https://access.redhat.com/errata/RHSA-2026:17668
2026-07-30
Published