SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18000

LOW · CVSS 3.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Insufficient policy enforcement in the USB functionality of Google Chrome on Android versions prior to 151.0.7922.72 allows remote attackers to exploit a compromised renderer process, potentially leaking cross-origin data through specially crafted HTML pages. While the severity is rated low, organizations using affected versions should prioritize updates to mitigate the risk of data exposure. Users and administrators of Android devices running Chrome should ensure they are on the latest version to protect against this vulnerability.

CVE
CVE-2026-18000
Severity
LOW
CVSS
3.1
EPSS
0.15%
Android Chrome

Original NVD Description

Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

Related CVEs

Other vulnerabilities affecting the same vendor(s)