Description
Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from an inappropriate implementation in Chrome extensions, allowing an attacker who persuades a user to install a malicious extension to read and leak cross‑origin data. The weakness is a form of improper access control (CWE‑284) and an authorization bypass through user‑controlled keys (CWE‑346). The consequence is that private information originating from other domains can be exfiltrated, potentially exposing sensitive user data without the user’s awareness.

Affected Systems

The flaw exists in Google Chrome versions prior to 151.0.7922.72. Any user running an affected build of the Chrome browser and installing an extension can be impacted.

Risk and Exploitability

With a CVSS score of 4.3 the severity is medium. The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of active exploitation at this time. Exploitation requires social engineering to convince a user to install a crafted extension; a successful attack would grant unauthorized cross‑origin data access rather than remote code execution.

Generated by OpenCVE AI on August 3, 2026 at 12:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest stable Chrome release that includes the 151.0.7922.72 update or newer to eliminate the flaw.
  • Review existing extensions and remove or disable any that request unnecessary cross‑origin permissions.
  • If a suspicious extension is present, uninstall it immediately to prevent potential data leakage.
  • Maintain Chrome’s update channel to receive future mitigations as they are released.

Generated by OpenCVE AI on August 3, 2026 at 12:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in Extensions
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 30 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T17:57:51.956Z

Reserved: 2026-07-27T23:34:44.307Z

Link: CVE-2026-17781

cve-icon Vulnrichment

Updated: 2026-07-30T17:57:45.627Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:41.407

Modified: 2026-08-03T17:56:04.337

Link: CVE-2026-17781

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:19Z

Links: CVE-2026-17781 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:15:03Z

Weaknesses