Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)
CVE-2026-17987
NONE
EPSS 0.16%
Updated Jul 30, 2026
Google
google:chrome
CVE Details
CVE ID
CVE-2026-17987
Published Date
Jul 30, 2026
Vendor
Google
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.16%
Likelihood of exploitation in next 30 days
Percentile:
5.7th percentile (higher than 5.7% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory