PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17860 Google CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:49.777Z and has not been modified since then. This vulnerability affects Google Chrome on Android, allowing local attackers to spoof the Omnibox (URL bar) via a malicious file due to insufficient validation of untrusted input. The issue is classified as Medium severity by Chromium. Users of Google Chrome on Android, particularly those who may be targeted by local attackers, should ensure they are running version 151.0.7922.72 or later. This includes individuals and organizations using Google Chrome for browsing, as the vulnerability could allow attackers to spoof the URL bar, potentially leading to phishing or other malicious activities. IT administrators should prioritize updating Chrome to the latest version and monitor for any suspicious activity related to malicious files on Android devices used within their environments.

Vendor
Google
Product
Chrome
CVSS
LOW 3.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-07-31
Advisory published
2026-07-30
Advisory updated
2026-07-31

Who should care

Users of Google Chrome on Android, particularly those who may be targeted by local attackers, should ensure they are running version 151.0.7922.72 or later. This includes individuals and organizations using Google Chrome for browsing, as the vulnerability could allow attackers to spoof the URL bar, potentially leading to phishing or other malicious activities. IT administrators should prioritize updating Chrome to the latest version and monitor for any suspicious activity related to malicious files on Android devices used within their environments.

Technical summary

Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a malicious file. This issue is classified as Medium severity by Chromium. The vulnerability affects Google Chrome on Android, highlighting the need for users to update to version 151.0.7922.72 or later to mitigate the risk.

Defensive priority

Low-priority defensive review recommended due to limited attack surface.

Recommended defensive actions

  • Review and apply Google Chrome updates to ensure version 151.0.7922.72 or later is installed.
  • Implement strict input validation for untrusted input in mobile applications.
  • Monitor for suspicious activity related to malicious files on Android devices.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from official sources indicates insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72. Local attackers may spoof the Omnibox (URL bar) via a malicious file. Chromium security severity is Medium. The CVE record was published on 2026-07-30T01:16:49.777Z and has not been modified since then. However, defenders should verify the accuracy of this information within their specific environments and review official advisories for the most current details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:49.777Z and has not been modified since then.