SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17999

MEDIUM · CVSS 6.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A race condition in the Picture-in-Picture feature of Google Chrome on Android versions prior to 151.0.7922.72 enables remote attackers to exploit domain spoofing through specially crafted HTML pages. This vulnerability could lead to phishing attacks or misrepresentation of web content, impacting users who rely on the affected browser. Organizations and developers utilizing Chrome on Android should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-17999
Severity
MEDIUM
CVSS
6.5
EPSS
0.15%
Android Chrome

Original NVD Description

Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

Related CVEs

Other vulnerabilities affecting the same vendor(s)