CVE-2026-18019CWE-1300

CVE-2026-18019

Medium · published July 30, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
5.8
In the wild
Unconfirmed
What it is

Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00163 · 5.8th percentile
Weakness
CWE-1300 · Improper Protection of Physical Side Channels
Published
2026-07-30T05:17Z
Affected products (1)
ProductVersionsFixed in
google/chrome< 151.0.7922.72151.0.7922.72
References (2)
EPSS history
Timeline
  • 30 JUL 00:26Z
    Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page
    cvelistv5