Description
Inappropriate implementation in ReportingAndNEL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an inappropriate implementation in the ReportingAndNEL component of Google Chrome. The flaw, classified as CWE-346, permits a remote attacker to construct a crafted HTML page that can exfiltrate cross‑origin data from the victim’s browser. The attacker does not gain code execution or elevated privileges; instead the exposed information could reveal sensitive user data or private network resources accessible through the browser.

Affected Systems

Google Chrome consumer builds prior to version 151.0.7922.72 are affected. The fix was released in the stable channel update for desktop versions 151.0.7922.72 and later.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity issue that primarily leads to information disclosure. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. The attack most likely requires a user to open or interact with a malicious web page crafted by the attacker; a compromised or malicious site could serve the exploit. Because the weakness is client‑side, mitigation focuses on preventing exposure to the vulnerable browsers rather than preventing server‑side impact.

Generated by OpenCVE AI on August 3, 2026 at 12:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or later.
  • Verify that automatic updates are enabled and that browsers are kept current on all endpoint devices.
  • Use enterprise policy to disable the ReportingAndNEL feature or otherwise block exfiltration traffic if the feature is not needed for business operations.

Generated by OpenCVE AI on August 3, 2026 at 12:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in ReportingAndNEL
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 30 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in ReportingAndNEL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T17:47:51.916Z

Reserved: 2026-07-27T23:34:56.540Z

Link: CVE-2026-17817

cve-icon Vulnrichment

Updated: 2026-07-30T17:47:47.967Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:45.257

Modified: 2026-08-03T17:42:01.053

Link: CVE-2026-17817

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:29Z

Links: CVE-2026-17817 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:15:03Z

Weaknesses