CVE-2026-17670

9.6

Google · Chrome

A use after free vulnerability in the Views component of Google Chrome allows a remote attacker to perform a sandbox escape after compromising the renderer process.

Executive summary

A critical use after free flaw in Google Chrome's Views component enables remote attackers to escape the sandbox, resulting in a high risk of total system compromise.

Vulnerability

This is a use after free vulnerability (CWE-416) in the Views component. An unauthenticated attacker can exploit this via a crafted HTML page, provided they have first successfully compromised the renderer process.

Business impact

With a CVSS score of 9.6, this vulnerability represents a significant threat to organizational security. By escaping the sandbox, an attacker can transition from a limited browser process to executing arbitrary code with the privileges of the user, leading to potential data exfiltration and persistent system access.

Remediation

Immediate Action: Update Google Chrome to version 151.0.7922.72 or higher to resolve the vulnerability.

Proactive Monitoring: Monitor for unexpected browser behavior or unusual spikes in memory usage, which may be indicative of exploitation attempts.

Compensating Controls: Implement strict endpoint security policies that limit the ability of browser processes to interact with sensitive system APIs.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this issue necessitates an immediate patching cycle across all enterprise workstations. Organizations should ensure that automatic updates for Chrome are enabled and verified.

More Google CVEs