SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17728

MEDIUM · CVSS 5.4 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A vulnerability in Google Chrome's Extensions prior to version 151.0.7922.72 allows remote attackers to inject arbitrary scripts or HTML through a specially crafted HTML page, leading to potential user experience security issues (UXSS). This could enable attackers to manipulate web content or steal sensitive information from users. Organizations using affected versions of Chrome should prioritize updating to mitigate the risk of exploitation.

CVE
CVE-2026-17728
Severity
MEDIUM
CVSS
5.4
EPSS
0.29%
Chrome

Original NVD Description

Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)