Description
Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

While a media component in older Chrome versions stored sensitive data unprotected, this issue leads to side‑channel leaks that can disclose cross‑origin information to an attacker who serves a specifically crafted web page. The flaw is a result of improper isolation between media buffers, classified as CWE‑1300, and does not require privileged execution. The potential consequences are limited to confidentiality of content accessible through the victim’s browser session rather than arbitrary code execution or privilege escalation.

Affected Systems

The affected product is Google Chrome, any version earlier than 151.0.7922.72, across all desktop platforms, and is listed by CNA as Google:Chrome. All users of the unstable, beta, stable channel could be impacted until the new channel release.

Risk and Exploitability

The CVSS score of 4.3 categorizes the weakness as low‑to‑medium severity, and the EPSS score is below 1 %, meaning current empirical exploitability is thought to be minimal. The vulnerability is not present in the CISA KEV catalog. A likely attack path is a remote web page that tricks the victim into loading media content, thereby inducing the side‑channel leak. Given the low exploitation probability, monitoring for signs of abuse may be sufficient until a security update is applied.

Generated by OpenCVE AI on August 2, 2026 at 05:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or later as released by the stable channel.
  • If an immediate upgrade is unavailable, enforce an enterprise policy that disables or restricts Media features to prevent cross‑origin resource sharing.
  • Keep the browser updated to the latest security releases and monitor Google’s security advisories for further information.

Generated by OpenCVE AI on August 2, 2026 at 05:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leakage of Cross‑Origin Data via Crafted HTML Page in Google Chrome chromium-browser: chromium-browser: Side-channel information leakage in Media
Weaknesses CWE-205
References
Metrics threat_severity

None

threat_severity

Low


Fri, 31 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leakage of Cross‑Origin Data via Crafted HTML Page in Google Chrome

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-1300
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T14:21:25.452Z

Reserved: 2026-07-27T23:37:19.509Z

Link: CVE-2026-18019

cve-icon Vulnrichment

Updated: 2026-07-30T14:07:15.692Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:17:06.713

Modified: 2026-08-03T15:55:28.150

Link: CVE-2026-18019

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-30T00:26:10Z

Links: CVE-2026-18019 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:45:03Z

Weaknesses
  • CWE-1300

    Improper Protection of Physical Side Channels

  • CWE-205

    Observable Behavioral Discrepancy