CVE-2026-17730
published 2026-07-30CVE-2026-17730: Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.24%
15.6th percentile
Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 151.0.7922.72 | 151.0.7922.72 | |
| chrome | >= 151.0.7922.72 < 151.0.7922.72 | 151.0.7922.72 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: chromium-browser: Side-channel information leakage in Autofill
vendor_redhat·2026-07-30·CVSS 4.3
CVE-2026-17730 [MEDIUM] CWE-346 chromium-browser: chromium-browser: Side-channel information leakage in Autofill
chromium-browser: chromium-browser: Side-channel information leakage in Autofill
A side-channel information leakage flaw was found in the Autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=40057032
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-17730
vendor_chrome·2026-07-29
CVE-2026-17730 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-17730
Stable Channel Update for Desktop
CVE-2026-17730: Side-channel information leakage in Autofill. Reported by Google on 2021-08-26 [TBD][ 463551850 ] Medium CVE-2026-17731: Inappropriate implementation in Autofill
Reported by Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies on 2025-11-25 [N/A][ 495793059 ] Medium CVE-2026-17733: Inappropriate implementation in QUIC
Severity: medium
VulDB
Google Chrome up to 150.0.7871.186 Autofill information disclosure (Nessus ID 331578)
vuldb·2026-08-03·CVSS 4.3
CVE-2026-17730 [MEDIUM] Google Chrome up to 150.0.7871.186 Autofill information disclosure (Nessus ID 331578)
A vulnerability marked as problematic has been reported in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Autofill. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-17730. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a cr
ghsa_unreviewed·2026-07-30
CVE-2026-17730 [MEDIUM] CWE-1300 Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a cr
Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
2026-07-30
Published