Description
Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an inappropriate implementation in Chrome’s Media Router that allows a remote attacker to bypass the same‑origin policy by loading a specially crafted HTML page. The vulnerability is classified as CWE‑346, broken access control, and permits an attacker to read or execute data that should be confined to the browser’s origin sandbox, potentially exposing sensitive information or enabling further exploitation.

Affected Systems

Affected systems are Google Chrome browsers on desktop platforms running a version earlier than 151.0.7922.72. The vulnerability exists in the stable channel releases; users should verify that their build is older than this version and plan to upgrade.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of recent exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deploy a malicious HTML page and persuade a user to open it; once the Media Router processes the request, the same‑origin restrictions are bypassed. The attack vector is a web‑content vector, requiring no elevated privileges.

Generated by OpenCVE AI on August 2, 2026 at 06:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or newer.
  • If an upgrade cannot be performed immediately, launch Chrome with the flag --disable-features=MediaRouter or use enterprise policy to block the MediaRouter feature.
  • Implement a strict Content Security Policy that restricts cross‑origin media requests to mitigate potential abuse.

Generated by OpenCVE AI on August 2, 2026 at 06:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in Media Router
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}

threat_severity

Moderate


Thu, 30 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T18:22:27.671Z

Reserved: 2026-07-27T23:35:04.591Z

Link: CVE-2026-17852

cve-icon Vulnrichment

Updated: 2026-07-31T18:22:22.088Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:48.873

Modified: 2026-08-03T19:40:43.853

Link: CVE-2026-17852

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:39Z

Links: CVE-2026-17852 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:45:03Z

Weaknesses