SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-17860

LOW · CVSS 3.3 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A vulnerability in Google Chrome on Android prior to version 151.0.7922.72 allows local attackers to spoof the Omnibox (URL bar) contents through insufficient validation of untrusted input from a malicious file. While the severity is classified as low, the potential for misleading users about the authenticity of URLs could lead to phishing attacks. Android users and developers should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-17860
Severity
LOW
CVSS
3.3
EPSS
0.09%
Android Chrome

Original NVD Description

Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a malicious file. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)