SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17754

MEDIUM · CVSS 6.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A vulnerability in the Blink engine of Google Chrome allows remote attackers to bypass the same-origin policy through a specially crafted HTML page, potentially leading to unauthorized access to sensitive data. This issue affects versions prior to 151.0.7922.72 and could enable exploitation in web applications that rely on this security feature. Organizations using affected versions of Chrome should prioritize updating to mitigate the risk of data exposure.

CVE
CVE-2026-17754
Severity
MEDIUM
CVSS
6.5
EPSS
0.28%
Chrome

Original NVD Description

Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)