PT-2026-66009 · Google · Chrome On Android

CVE-2026-17690

·

Published

2026-07-30

·

Updated

2026-08-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome on Android versions prior to 151.0.7922.72
Description Insufficient validation of untrusted input in the PDF component allows a local attacker to leak cross-origin data through a crafted HTML page. Cross-origin data leakage occurs when a malicious site accesses information from a different origin than the one that served the page, violating the Same-Origin Policy.
Recommendations Update Google Chrome on Android to version 151.0.7922.72 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17690
ECHO-39BF-3C91-30F7
OPENSUSE-SU-2026:11434-1
OPENSUSE-SU-2026:21514-1

Affected Products

Chrome On Android