Google Chrome Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities have been identified in Google Chrome.
- Who is affected
- Users of Google Chrome are affected.
- Urgency
- Remediation is not urgent as there are no known exploits for these vulnerabilities.
- Action
- Ensure Chrome is updated to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/google-chrome-multiple-vulnerabilities_20260730
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-176500.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-176510.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-176520.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-176530.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-176540.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Low exploitation riskCVE-2026-176550.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-176560.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-176570.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all scored CVEs.
- Low exploitation riskCVE-2026-176580.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-176590.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownDSA-6408-1 chromium - security updatedebian
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund
- criticalCVE-2026-17709: Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who…nvd
- criticalCVE-2026-17708: Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who …nvd
- mediumCVE-2026-17707: Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote…nvd
- mediumCVE-2026-17706: Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0…nvd
- highCVE-2026-17705: Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker t…nvd
- criticalCVE-2026-17704: Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who …nvd
- mediumCVE-2026-17703: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…nvd
- lowCVE-2026-17702: Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote …nvd
- criticalCVE-2026-17701: Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.792…nvd
- mediumCVE-2026-17700: Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 al…nvd
More from HKCERT Security Bulletins
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-07-30
- unknownCisco Secure Firewall Management Center Software Information Disclosure Vulnerability2026-07-30
- unknownNode.js Multiple Vulnerabilities2026-07-30
- unknownXen Multiple Vulnerabilities2026-07-30
- unknownCitrix XenServer Multiple Vulnerabilities2026-07-30