CVE-2026-17907
published 2026-07-30CVE-2026-17907: Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.19%
9.3th percentile
Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 151.0.7922.72 | 151.0.7922.72 | |
| chrome | >= 151.0.7922.72 < 151.0.7922.72 | 151.0.7922.72 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Google Chrome: Information leakage via crafted HTML page
vendor_redhat·2026-07-30·CVSS 4.3
CVE-2026-17907 [MEDIUM] CWE-346 chromium-browser: Google Chrome: Information leakage via crafted HTML page
chromium-browser: Google Chrome: Information leakage via crafted HTML page
A flaw was found in Google Chrome's Network component. A remote attacker could exploit this side-channel information leakage vulnerability by enticing a user to visit a specially crafted HTML page. This could allow the attacker to leak sensitive cross-origin data.
Statement: This Moderate-severity flaw in the Chromium browser's network component allows a remote attacker to leak cross-origin data. Exploitation requires a user to visit a specially crafted HTML page, limiting the impact to information disclosure rather than arbitrary code execution. Red Hat users running Chromium are affected if they browse untrusted web content.
Chrome
Stable Channel Update for Desktop: CVE-2026-17905
vendor_chrome·2026-07-29
CVE-2026-17905 [LOW] Stable Channel Update for Desktop: CVE-2026-17905
Stable Channel Update for Desktop
CVE-2026-17905: Inappropriate implementation in SurfaceCapture. Reported by Google on 2026-03-29 [N/A][ 497654761 ] Low CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth
Reported by Google on 2026-03-30 [N/A][ 497837927 ] Low CVE-2026-17907: Side-channel information leakage in Network
Severity: low
GHSA
Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ghsa_unreviewed·2026-07-30
CVE-2026-17907 [MEDIUM] CWE-1300 Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-17907 chromium-browser: Google Chrome: Information leakage via crafted HTML page
bugzilla·2026-07-30·CVSS 4.3
CVE-2026-17907 [MEDIUM] CVE-2026-17907 chromium-browser: Google Chrome: Information leakage via crafted HTML page
CVE-2026-17907 chromium-browser: Google Chrome: Information leakage via crafted HTML page
Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Bugzilla
CVE-2026-17907 chromium: Google Chrome: Information leakage via crafted HTML page [epel-all]
bugzilla·2026-07-30·CVSS 4.3
CVE-2026-17907 [MEDIUM] CVE-2026-17907 chromium: Google Chrome: Information leakage via crafted HTML page [epel-all]
CVE-2026-17907 chromium: Google Chrome: Information leakage via crafted HTML page [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Bugzilla
CVE-2026-17907 chromium: Google Chrome: Information leakage via crafted HTML page [fedora-all]
bugzilla·2026-07-30·CVSS 4.3
CVE-2026-17907 [MEDIUM] CVE-2026-17907 chromium: Google Chrome: Information leakage via crafted HTML page [fedora-all]
CVE-2026-17907 chromium: Google Chrome: Information leakage via crafted HTML page [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
2026-07-30
Published