[NEW] [high] Google Chrome: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary code, disclose confidential information, bypass security measures, manipulate data, or trigger a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to execute arbitrary code, disclose confidential information, bypass security measures, manipulate data, or trigger a denial-of-service condition.
- Who is affected
- Users of Google Chrome.
- Urgency
- Remediation is high urgency due to the potential for severe impacts including arbitrary code execution and data disclosure.
- Action
- Update Google Chrome to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2579
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-176500.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-176510.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-176520.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-176530.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all scored CVEs.
- Low exploitation riskCVE-2026-176540.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
- Low exploitation riskCVE-2026-176550.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-176560.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all scored CVEs.
- Low exploitation riskCVE-2026-176570.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all scored CVEs.
- Low exploitation riskCVE-2026-176580.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-176590.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownDSA-6408-1 chromium - security updatedebian
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- criticalCVE-2026-17709: Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who…nvd
- criticalCVE-2026-17708: Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who …nvd
- mediumCVE-2026-17707: Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote…nvd
- mediumCVE-2026-17706: Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0…nvd
- highCVE-2026-17705: Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker t…nvd
- criticalCVE-2026-17704: Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who …nvd
- mediumCVE-2026-17703: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…nvd
- lowCVE-2026-17702: Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote …nvd
- criticalCVE-2026-17701: Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.792…nvd
- mediumCVE-2026-17700: Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 al…nvd
Recent advisories for Google Chrome
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert · 2026-07-30
- mediumCVE-2026-18019: Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a re…nvd · 2026-07-30
- mediumCVE-2026-18018: Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 all…nvd · 2026-07-30
- highCVE-2026-18017: Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex…nvd · 2026-07-30
- mediumCVE-2026-18016: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…nvd · 2026-07-30
- criticalCVE-2026-18015: Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a …nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31