Description
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Inappropriately implemented view handling in Google Chrome for macOS enabled a local adversary to read sensitive data from process memory. By loading a specially crafted HTML page, an attacker can trigger the flaw and obtain confidential information. The weakness falls under CWE-200, an information exposure flaw, and the impact is limited to confidentiality loss for the user’s data within the local environment.

Affected Systems

The vulnerable product is Google Chrome on macOS, versions older than 151.0.7922.72. Any Chrome build prior to 151.0.7922.72 on macOS is susceptible.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires a local attacker who can open or inject the crafted HTML page within Chrome, so the attack vector is local and confined to the user's machine.

Generated by OpenCVE AI on August 2, 2026 at 05:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 151.0.7922.72 or later on macOS.
  • Configure Chrome or the operating system to prevent automatic opening of untrusted local HTML files.
  • Ensure that no malicious or suspicious local HTML content remains on the system.

Generated by OpenCVE AI on August 2, 2026 at 05:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Local Browser View Memory Disclosure on Mac via Crafted HTML chromium-browser: chromium-browser: Inappropriate implementation in Views
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Low


Fri, 31 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Browser View Memory Disclosure on Mac via Crafted HTML

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T19:26:33.842Z

Reserved: 2026-07-27T23:37:11.063Z

Link: CVE-2026-17973

cve-icon Vulnrichment

Updated: 2026-07-30T19:26:29.554Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:17:01.850

Modified: 2026-08-03T17:16:20.727

Link: CVE-2026-17973

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-30T00:25:50Z

Links: CVE-2026-17973 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:00:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-825

    Expired Pointer Dereference