SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17707

MEDIUM · CVSS 6.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Google Chrome on Windows prior to version 151.0.7922.72 is vulnerable due to an uninitialized use in the Media component, which allows remote attackers to exploit the renderer process and access sensitive information from process memory through specially crafted HTML pages. This vulnerability poses a medium risk, but its classification as high severity in the Chromium security context indicates that organizations handling sensitive data should prioritize patching to mitigate potential data leaks. Users and administrators of affected systems should update their Chrome installations promptly to safeguard against this exploit.

CVE
CVE-2026-17707
Severity
MEDIUM
CVSS
6.5
EPSS
0.49%
Windows Chrome

Original NVD Description

Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)