CVE-2026-17978CWE-1300

CVE-2026-17978

Medium · published July 30, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
11.3
In the wild
Unconfirmed
What it is

Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00211 · 11.3th percentile
Weakness
CWE-1300 · Improper Protection of Physical Side Channels
Published
2026-07-30T05:17Z
Affected products (1)
ProductVersionsFixed in
google/chrome< 151.0.7922.72151.0.7922.72
References (2)
EPSS history
Timeline
  • 30 JUL 00:25Z
    Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information…
    cvelistv5