PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17895 Google CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T01:16:53.533Z and has not been modified since then. The CVE-2026-17895 vulnerability in Google Chrome's DataTransfer implementation allows a remote attacker to leak cross-origin data via a crafted HTML page, requiring user interaction. The vulnerability has a CVSS score of 4.3 and is classified as CWE-346. It affects Google Chrome prior to version 151.0.7922.72. The vulnerability is medium severity and requires user interaction to leak cross-origin data. Organizations and individuals using Google Chrome prior to version 151.0.7922.72 should update to the latest version to mitigate this vulnerability. Additionally, users should be cautious when interacting with untrusted web pages. IT teams and security professionals should prioritize patching and monitor for suspicious user interactions with HTML pages from untrusted sources. This vulnerability may impact organizations using Chrome for critical operations or sensitive data processing.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-30
Original CVE updated
2026-08-03
Advisory published
2026-07-30
Advisory updated
2026-08-03

Who should care

Organizations and individuals using Google Chrome prior to version 151.0.7922.72 should update to the latest version to mitigate this vulnerability. Additionally, users should be cautious when interacting with untrusted web pages. IT teams and security professionals should prioritize patching and monitor for suspicious user interactions with HTML pages from untrusted sources. This vulnerability may impact organizations using Chrome for critical operations or sensitive data processing.

Technical summary

The CVE-2026-17895 vulnerability in Google Chrome's DataTransfer implementation allows a remote attacker to leak cross-origin data via a crafted HTML page, requiring user interaction. The vulnerability has a CVSS score of 4.3 and is classified as CWE-346. It affects Google Chrome prior to version 151.0.7922.72. The vulnerability is medium severity and requires user interaction to leak cross-origin data.

Defensive priority

Medium severity vulnerability in Google Chrome, requiring user interaction to leak cross-origin data.

Recommended defensive actions

  • Inventory and verify Google Chrome versions prior to 151.0.7922.72 are updated to the latest version.
  • Monitor for and restrict suspicious user interactions with HTML pages from untrusted sources.
  • Implement compensating controls such as network segmentation and access controls.
  • Educate users about the risks of engaging in specific UI gestures on untrusted web pages.
  • Review and update incident response plans to address potential data leaks.

Evidence notes

The CVE-2026-17895 record indicates a medium severity vulnerability in Google Chrome's DataTransfer implementation, allowing cross-origin data leaks with user interaction. Official sources include CVE.org, NVD, and Google's release notes. The vulnerability requires user interaction and has a CVSS score of 4.3. Defenders should verify Chrome versions, monitor user interactions, and implement compensating controls. Evidence is limited to publicly available sources and CVE details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17895 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17895

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17895 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17895

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.