PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17730 Google CVE debrief

The CVE-2026-17730 vulnerability is a side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72. This allows a remote attacker to leak cross-origin data by convincing a user to engage in specific UI gestures via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is rated as Medium severity by Chromium. Affected product deployments should be reviewed for exposure, and owners should be assigned for follow-up. The vulnerability class is related to side-channel information leakage, and the likely operational impact is cross-origin data leakage. The source-confidence limits are based on the Chromium security severity rating.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-07-31
Advisory published
2026-07-30
Advisory updated
2026-07-31

Who should care

Users of Google Chrome prior to version 151.0.7922.72, administrators of systems with Google Chrome installed, security teams monitoring for cross-origin data leakage vulnerabilities, and operators of affected platforms should review the vulnerability and take necessary actions. The vulnerability-management impact is that the vulnerability should be reviewed and patched. The security-team impact is that the vulnerability should be monitored and verified for exposure. The affected operator impact is that user interaction is required to leak cross-origin data. The platform impact is that Google Chrome prior to version 151.0.7922.72 is affected. The asset-inventory impact is that affected assets should be reviewed and patched. The change-management impact is that the patch should be applied through normal change control. The source-tracking impact is that the vulnerability should be tracked and verified for exposure. The compensating-controls impact is that compensating controls should be reviewed and implemented for exposed systems. The monitoring impact is that relevant monitoring, detection, and logs should be reviewed for exposed assets that need extra review. The rollback-change-windows impact is that exceptions should be tracked and retested, and remediated assets should be closed only after evidence is documented. The vendor-patch-guidance impact is that the patch should be applied to update Google Chrome to version 151.0.7922.72 or later. The exposure-review impact is that exposure should be reviewed and verified. The compensating-controls impact is that compensating controls should be implemented to detect and prevent cross-origin data leakage. The monitoring impact is that monitoring should be implemented to detect and prevent cross-origin data leakage. The asset-inventory impact is that asset inventory should be reviewed to identify affected assets. The rollback-change-windows impact is that rollback change windows should be implemented to track exceptions and retest remediated assets. The source-tracking impact is that source tracking should be implemented to track the vulnerability and verify exposure. The defensive-priority impact is that the medium 4

Technical summary

The CVE-2026-17730 vulnerability is a side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72. This allows a remote attacker to leak cross-origin data by convincing a user to engage in specific UI gestures via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is rated as Medium severity by Chromium. The affected product context is Google Chrome, and the defensive impact is that user interaction is required to leak cross-origin data. The source-grounded technical framing is based on the Chromium security severity rating.

Defensive priority

Medium severity vulnerability in Google Chrome, requiring user interaction to leak cross-origin data.

Recommended defensive actions

  • Apply the patch to update Google Chrome to version 151.0.7922.72 or later.
  • Restrict user access to sensitive data and monitor for suspicious activity.
  • Implement compensating controls to detect and prevent cross-origin data leakage.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE-2026-17730 vulnerability is described as a side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72. A remote attacker can exploit this by convincing a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. The Chromium security severity is rated as Medium with a CVSS score of 4.3.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:35.707Z and has not been modified since then.