SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17737

MEDIUM · CVSS 5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the Bluetooth component of Google Chrome on Android prior to version 151.0.7922.72 allows remote attackers to exploit the renderer process, potentially leading to a sandbox escape through a specially crafted HTML page. This issue poses a medium risk, and organizations using affected versions of Chrome on Android should prioritize patching to mitigate the risk of remote exploitation.

CVE
CVE-2026-17737
Severity
MEDIUM
CVSS
5
EPSS
0.26%
Android Chrome

Original NVD Description

Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)