CVE-2026-17731
published 2026-07-30CVE-2026-17731: Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.20%
10.2th percentile
Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 151.0.7922.72 | 151.0.7922.72 | |
| chrome | >= 151.0.7922.72 < 151.0.7922.72 | 151.0.7922.72 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: chromium-browser: Inappropriate implementation in Autofill
vendor_redhat·2026-07-30·CVSS 4.3
CVE-2026-17731 [MEDIUM] CWE-940 chromium-browser: chromium-browser: Inappropriate implementation in Autofill
chromium-browser: chromium-browser: Inappropriate implementation in Autofill
An inappropriate implementation flaw was found in the Autofill component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=463551850
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-17730
vendor_chrome·2026-07-29
CVE-2026-17730 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-17730
Stable Channel Update for Desktop
CVE-2026-17730: Side-channel information leakage in Autofill. Reported by Google on 2021-08-26 [TBD][ 463551850 ] Medium CVE-2026-17731: Inappropriate implementation in Autofill
Reported by Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies on 2025-11-25 [N/A][ 495793059 ] Medium CVE-2026-17733: Inappropriate implementation in QUIC
Severity: medium
VulDB
Google Chrome up to 150.0.7871.186 Autofill cross-domain policy (Nessus ID 331578)
vuldb·2026-08-03·CVSS 4.3
CVE-2026-17731 [MEDIUM] Google Chrome up to 150.0.7871.186 Autofill cross-domain policy (Nessus ID 331578)
A vulnerability was found in Google Chrome. It has been rated as problematic. The impacted element is an unknown function of the component Autofill. This manipulation causes permissive cross-domain policy with untrusted domains.
This vulnerability is handled as CVE-2026-17731. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ghsa_unreviewed·2026-07-30
CVE-2026-17731 [MEDIUM] CWE-346 Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
2026-07-30
Published