Description
Inappropriate implementation in SurfaceCapture in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper implementation of the SurfaceCapture feature in Google Chrome allows a remote attacker to leak data from a different origin by serving a specially crafted HTML page. The flaw permits the browser to capture and expose cross‑origin content, resulting in a confidentiality breach for users who load the malicious page. The vulnerability is classified under CWE‑346 (Data from Untrusted Origin Used in Operation) and CWE‑940 (Direct Data Leak from Protected Source).

Affected Systems

All installations of Google Chrome running a version older than 151.0.7922.72 on any operating system are affected. Any user who visits a malicious page without updating the browser risks disclosure of cross‑origin information.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity impact, and the EPSS score of less than 1 % shows a very low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a crafted web page that the victim visits, but no advanced privileges or local code execution are needed. The principal attack vector is remote through user interaction with a malicious website.

Generated by OpenCVE AI on August 2, 2026 at 06:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or newer, which contains the SurfaceCapture patch.
  • If an update is not immediately possible, apply a Chrome policy to disable SurfaceCapture or restrict the browser from loading untrusted content.
  • Educate users and monitor for unusual cross‑origin data requests that could indicate exploitation attempts.

Generated by OpenCVE AI on August 2, 2026 at 06:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in SurfaceCapture
Weaknesses CWE-940
References
Metrics threat_severity

None

threat_severity

Low


Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in SurfaceCapture in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T17:56:16.673Z

Reserved: 2026-07-27T23:36:55.615Z

Link: CVE-2026-17905

cve-icon Vulnrichment

Updated: 2026-07-30T17:56:13.762Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:54.557

Modified: 2026-08-03T17:34:21.910

Link: CVE-2026-17905

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-30T00:25:21Z

Links: CVE-2026-17905 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:30:17Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-940

    Improper Verification of Source of a Communication Channel