CVE-2026-17650
Google · Chrome
A use after free vulnerability in the Compositing component of Google Chrome may permit arbitrary code execution when processing malicious content.
Executive summary
Google Chrome is vulnerable to a use after free flaw in the Compositing component that presents a significant risk of remote code execution.
Vulnerability
This is a use after free vulnerability (CWE-416) found in the Compositing component of the browser. The vulnerability can be exploited by an unauthenticated attacker, although it requires user interaction to successfully execute.
Business impact
The CVSS score of 8.3 indicates that this is a severe vulnerability. Successful exploitation could lead to the compromise of the user session, allowing attackers to access sensitive data or perform actions on behalf of the user, potentially escalating to full system compromise.
Remediation
Immediate Action: Update Google Chrome to version 151.0.7922.72 or later to remediate the vulnerability.
Proactive Monitoring: Monitor browser activity for unusual rendering behavior or crashes that may indicate an attempt to trigger a use after free condition.
Compensating Controls: Deploy web filtering and browser security policies to prevent users from navigating to untrusted or potentially malicious websites.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for remote code execution, it is imperative to update all Chrome installations to the specified version. Organizations should prioritize this update to prevent attackers from leveraging malicious web content to exploit browser memory management.