PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17858 Google CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:49.553Z and has not been modified since then. The vulnerability, identified as CVE-2026-17858, is an uninitialized use issue in WebNN within Google Chrome on Windows systems. This vulnerability exists prior to version 151.0.7922.72 and allows a remote attacker to leak cross-origin data by exploiting the vulnerability through a crafted HTML page. The CVSS score for this vulnerability is 4.3, indicating a Medium severity level according to the Chromium security severity rating. The affected product context suggests that Google Chrome users on Windows systems should prioritize updates. Defenders should verify the affected scope, review official advisories, and monitor for suspicious cross-origin requests. Evidence is limited to public sources and CVE details.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-08-03
Advisory published
2026-07-30
Advisory updated
2026-08-03

Who should care

System administrators and users of Google Chrome on Windows systems should be aware of this vulnerability and take necessary actions to update their browsers to the latest version. Additionally, developers and security teams should consider the potential impact of this vulnerability on their applications and infrastructure, focusing on cross-origin data leakage and potential security bypasses.

Technical summary

The vulnerability, identified as CVE-2026-17858, is an uninitialized use issue in WebNN within Google Chrome on Windows systems. This vulnerability exists prior to version 151.0.7922.72 and allows a remote attacker to leak cross-origin data by exploiting the vulnerability through a crafted HTML page. The CVSS score for this vulnerability is 4.3, indicating a Medium severity level according to the Chromium security severity rating. The affected product context suggests that Google Chrome users on Windows systems should prioritize updates.

Defensive priority

Medium severity vulnerability in Google Chrome, requiring immediate attention to prevent potential data leaks.

Recommended defensive actions

  • Apply the latest Google Chrome update (version 151.0.7922.72 or later) to mitigate the vulnerability.
  • Restrict access to sensitive data and monitor for suspicious cross-origin requests.
  • Implement additional security measures, such as Content Security Policy (CSP), to reduce the attack surface.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE-2026-17858 record indicates an uninitialized use vulnerability in WebNN in Google Chrome on Windows prior to version 151.0.7922.72. This vulnerability, with a CVSS score of 4.3, could allow a remote attacker to leak cross-origin data via a crafted HTML page. The Chromium security severity is rated as Medium. Defenders should verify the affected scope, review official advisories, and monitor for suspicious cross-origin requests. Evidence is limited to public sources and CVE details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17858 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17858

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17858 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17858

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.