CVE-2026-17680

9.6

Google · Chrome

A heap buffer overflow in the Color component of Google Chrome on ChromeOS allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A heap buffer overflow vulnerability in Google Chrome allows remote attackers to bypass the browser sandbox, presenting a critical risk to system integrity and data confidentiality.

Vulnerability

This vulnerability is a heap buffer overflow (CWE-122) located in the Color component of the browser. It allows an unauthenticated remote attacker who has already compromised the renderer process to escape the security sandbox through a malicious HTML page.

Business impact

The ability to escape the browser sandbox is a severe security failure that compromises the primary defense mechanism protecting the underlying operating system from malicious web content. With a CVSS score of 9.6, this flaw poses a critical risk, as successful exploitation could lead to full system compromise, unauthorized access to sensitive local files, and potential remote code execution on the host machine.

Remediation

Immediate Action: Update all Google Chrome instances to version 151.0.7922.72 or later immediately to incorporate the provided security fix.

Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process creation originating from the Chrome renderer.

Compensating Controls: Ensure that the browser sandbox remains enabled and configured with the strictest possible security policies to limit the potential impact of renderer-level compromises.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the nature of sandbox escape vulnerabilities, this issue represents a significant threat to organizational security. Administrators must prioritize the deployment of the update to version 151.0.7922.72 across all managed workstations to eliminate this attack vector and prevent potential system-wide compromise.

More Google CVEs

Sources