CVE-2026-17853: Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-17853
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-178530.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-17853 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Inappropriate implementation in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-18018: Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 all…nvd · 2026-07-30
- criticalCVE-2026-18015: Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a …nvd · 2026-07-30
- mediumCVE-2026-18013: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 …nvd · 2026-07-30
- lowCVE-2026-18011: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 …nvd · 2026-07-30
- mediumCVE-2026-18010: Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a re…nvd · 2026-07-30
- mediumCVE-2026-18008: Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a rem…nvd · 2026-07-30
More from NVD Recent CVEs
- unknownCVE-2026-9487: XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_x…2026-08-03
- unknownCVE-2026-9390: XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_si…2026-08-03
- highCVE-2026-69097: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing a…2026-08-03
- highCVE-2026-69096: OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docke…2026-08-03
- highCVE-2026-69095: OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path t…2026-08-03