CVE-2026-17687

9.6

Google · Chrome

A type confusion vulnerability in the ANGLE graphics component of Google Chrome allows a remote attacker to achieve a sandbox escape through a crafted HTML page.

Executive summary

Google Chrome versions prior to 151.0.7922.72 are vulnerable to a critical type confusion flaw that enables remote sandbox escape, posing a severe risk to system integrity.

Vulnerability

The vulnerability exists within the ANGLE graphics engine, where a type confusion issue allows an unauthenticated, remote attacker who has already compromised the renderer process to break out of the browser sandbox.

Business impact

Successful exploitation of this vulnerability results in a sandbox escape, granting an attacker the ability to execute arbitrary code outside the restricted browser environment. Given the CVSS score of 9.6, this flaw poses a critical threat to the underlying operating system, potentially leading to full system compromise, unauthorized data exfiltration, and significant reputational damage.

Remediation

Immediate Action: Update all instances of Google Chrome to version 151.0.7922.72 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected child processes spawned by the Chrome browser.

Compensating Controls: Ensure that browser-based security policies are enforced and utilize endpoint detection and response (EDR) solutions to identify anomalous behavior originating from the browser renderer process.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a critical security risk that necessitates immediate attention. Organizations should prioritize patching all Chrome installations to the latest stable version to neutralize the threat of sandbox escape and potential system-level compromise.

More Google CVEs

Sources