CVE-2026-17675

9.6

Google · Chrome

An out of bounds write vulnerability in the ANGLE component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A critical out of bounds write vulnerability in Google Chrome, identified as CVE-2026-17675, allows remote attackers to bypass the browser sandbox and execute arbitrary code.

Vulnerability

This vulnerability involves an out of bounds write error within the ANGLE graphics engine. An unauthenticated remote attacker can exploit this flaw by enticing a user to visit a malicious website, potentially leading to a sandbox escape after the renderer process is compromised.

Business impact

The ability to escape the browser sandbox poses a severe risk to organizational security, as it allows attackers to move beyond the browser environment to execute code on the underlying host operating system. Given the CVSS score of 9.6, this vulnerability represents a critical risk of full system compromise, including unauthorized data access and the potential for lateral movement within the network.

Remediation

Immediate Action: Update all Google Chrome instances to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for anomalous process behavior or unauthorized attempts to access system files originating from the browser process.

Compensating Controls: Ensure that browser isolation solutions or endpoint detection and response (EDR) tools are configured to detect and block suspicious child process spawning from web browsers.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical nature of this vulnerability and its potential for sandbox escape, organizations must prioritize the deployment of the Chrome update across all workstations. Prompt patching is the most effective way to eliminate the risk of remote code execution and maintain the integrity of host systems.

More Google CVEs

Sources