Description
Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Google Chrome’s implementation of the Presentation API allows a remote attacker to create a crafted HTML page that can read data from other origins. This results in a leakage of cross‑origin information, compromising the confidentiality of data that a user may have access to during normal browsing. The weakness has been identified as a failure to enforce the same‑origin policy, which is reflected by CWE‑346.

Affected Systems

Any user running Google Chrome at a version earlier than 151.0.7922.72 on any platform with the Presentation API enabled is exposed. The vulnerability applies to the stable channel prior to the July 2026 update and is independent of operating system or device type.

Risk and Exploitability

The CVSS score of 4.3 indicates medium severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a malicious HTML page that a victim opens in Chrome; no additional credentials or local access are required for a successful exploit.

Generated by OpenCVE AI on August 2, 2026 at 06:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or later to address the faulty PresentationAPI implementation.
  • Configure automatic updates or use group‑policy settings to ensure Chrome receives security patches promptly.
  • If a patch cannot be applied immediately, launch Chrome with the flag --disable-presentation to disable the API and mitigate the data‑leak risk while an official fix is pending.

Generated by OpenCVE AI on August 2, 2026 at 06:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in PresentationAPI
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T16:08:14.601Z

Reserved: 2026-07-27T23:34:42.972Z

Link: CVE-2026-17775

cve-icon Vulnrichment

Updated: 2026-07-30T13:24:06.183Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:40.777

Modified: 2026-08-04T14:31:10.250

Link: CVE-2026-17775

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:17Z

Links: CVE-2026-17775 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T07:00:07Z

Weaknesses