CVE-2026-17685
Google · Chrome
A use after free vulnerability exists in the Autofill component of Google Chrome, which may allow an unauthenticated remote attacker to execute arbitrary code.
Executive summary
A critical use after free vulnerability in the Google Chrome Autofill component presents a significant risk of arbitrary code execution for users.
Vulnerability
This vulnerability involves a use after free error within the Autofill feature of the browser. An unauthenticated attacker can exploit this memory corruption issue by convincing a user to visit a crafted website, which may result in arbitrary code execution.
Business impact
Successful exploitation allows an attacker to execute code with the privileges of the browser process, potentially leading to data exfiltration or unauthorized system access. The CVSS score of 8.8 underscores the severity of this issue, necessitating rapid remediation to protect organizational assets from exploitation.
Remediation
Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to patch the Autofill component.
Proactive Monitoring: Review security monitoring tools for signs of abnormal browser behavior or unexpected network connections originating from browser processes.
Compensating Controls: Implement organizational web filtering solutions to block access to known malicious or suspicious domains that may host exploit payloads.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The urgency of this update is high due to the potential for remote code execution. Administrators should ensure that all instances of Google Chrome are updated to the current stable release to mitigate this security risk effectively.