PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17825 Google CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:46.057Z and has not been modified since then. This vulnerability affects Google Chrome on Android prior to version 151.0.7922.72, allowing remote attackers to bypass discretionary access control via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity. Organizations and individuals using Google Chrome on Android, particularly those handling sensitive data or requiring strict access control, should prioritize updating to the latest version and implementing compensating controls.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-07-31
Advisory published
2026-07-30
Advisory updated
2026-07-31

Who should care

Organizations and individuals using Google Chrome on Android, particularly those handling sensitive data or requiring strict access control, should prioritize updating to the latest version and implementing compensating controls. This includes reviewing and updating incident response plans to address potential bypass of discretionary access control. IT teams and security professionals responsible for managing Google Chrome on Android deployments should take immediate action to verify and update their systems. Furthermore, organizations should consider conducting a thorough review of their current security posture to identify potential vulnerabilities and implement necessary controls to prevent exploitation.

Technical summary

Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allows remote attackers to bypass discretionary access control via a crafted HTML page. The vulnerability has a CVSS score of 6.5 and is classified as Medium severity. This issue affects Google Chrome on Android, particularly those handling sensitive data or requiring strict access control. To address this vulnerability, it is essential to update Google Chrome on Android to version 151.0.7922.72 or later. Additionally, implementing compensating controls such as monitoring for suspicious activity and restricting access to sensitive data can help mitigate the risk.

Defensive priority

Medium severity vulnerability in Google Chrome, requiring immediate attention to prevent potential bypass of discretionary access control.

Recommended defensive actions

  • Inventory and verify Google Chrome on Android versions, checking for updates to 151.0.7922.72 or later.
  • Implement compensating controls, such as monitoring for suspicious activity and restricting access to sensitive data.
  • Review and update incident response plans to address potential bypass of discretionary access control.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from official vulnerability databases and source references indicate insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72. Limited details are available on affected scope and vendor remediation. Further review of system logs and monitoring for suspicious activity is recommended to verify the impact of this vulnerability. Additionally, defenders should verify that Google Chrome on Android versions are updated to 151.0.7922.72 or later, and consider implementing compensating controls such as restricting access to sensitive data.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:46.057Z and has not been modified since then.