Description
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-30
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an insufficient validation of untrusted input in the Passwords component of Google Chrome. When a remote attacker has already compromised the renderer process, a specially crafted HTML page can be used to bypass site isolation.

Affected Systems

Google Chrome versions earlier than 151.0.7922.72 are affected. All systems running these versions are susceptible until the update is applied.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity level, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to compromise the renderer process first, which can occur through unrelated vulnerabilities or social engineering, and then deliver a crafted page to bypass site isolation.

Generated by OpenCVE AI on August 3, 2026 at 12:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update (151.0.7922.72 or newer) to apply the fixed validation logic.
  • Ensure that automatic updates are enabled to receive future security fixes promptly.
  • Perform a system-wide malware scan to detect any compromise of renderer processes and verify the integrity of the updated browser installation.

Generated by OpenCVE AI on August 3, 2026 at 12:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Insufficient validation of untrusted input in Passwords
Weaknesses CWE-807
References
Metrics threat_severity

None

threat_severity

Important


Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T15:09:05.824Z

Reserved: 2026-07-27T23:34:22.688Z

Link: CVE-2026-17686

cve-icon Vulnrichment

Updated: 2026-07-30T15:08:59.129Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:30.880

Modified: 2026-08-03T17:59:32.487

Link: CVE-2026-17686

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-30T00:18:53Z

Links: CVE-2026-17686 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision