CVE-2026-17724
published 2026-07-30CVE-2026-17724: Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML…
PriorityP420medium4.2CVSS 3.1
AVNACHPRNUIRSUCLILAN
EPSS
0.15%
4.9th percentile
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | >= 151.0.7922.72 < 151.0.7922.72 | 151.0.7922.72 | |
| chrome_desktop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 150.0.7871.186 cross site scripting (Nessus ID 331578)
vuldb·2026-08-03·CVSS 4.2
CVE-2026-17724 [MEDIUM] Google Chrome up to 150.0.7871.186 cross site scripting (Nessus ID 331578)
A vulnerability was found in Google Chrome. It has been classified as problematic. Impacted is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-17724. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
ghsa_unreviewed·2026-07-30
CVE-2026-17724 [MEDIUM] CWE-362 Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
Chrome
Stable Channel Update for Desktop: CVE-2026-17722
vendor_chrome·2026-07-29
CVE-2026-17722 [HIGH] Stable Channel Update for Desktop: CVE-2026-17722
Stable Channel Update for Desktop
CVE-2026-17722: Object lifecycle issue in WebView. Reported by Google on 2026-06-13 [N/A][ 523718303 ] High CVE-2026-17723: Use after free in Media
Reported by Google on 2026-06-14 [N/A][ 523720739 ] High CVE-2026-17724: Race in Chrome for iOS
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-30
Published