CVE-2026-17687
9.6Google · Chrome
A type confusion vulnerability in the ANGLE graphics component of Google Chrome allows a remote attacker to achieve a sandbox escape through a crafted HTML page.
Executive summary
Google Chrome versions prior to 151.0.7922.72 are vulnerable to a critical type confusion flaw that enables remote sandbox escape, posing a severe risk to system integrity.
Vulnerability
The vulnerability exists within the ANGLE graphics engine, where a type confusion issue allows an unauthenticated, remote attacker who has already compromised the renderer process to break out of the browser sandbox.
Business impact
Successful exploitation of this vulnerability results in a sandbox escape, granting an attacker the ability to execute arbitrary code outside the restricted browser environment. Given the CVSS score of 9.6, this flaw poses a critical threat to the underlying operating system, potentially leading to full system compromise, unauthorized data exfiltration, and significant reputational damage.
Remediation
Immediate Action: Update all instances of Google Chrome to version 151.0.7922.72 or later immediately to apply the vendor-supplied security patch.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected child processes spawned by the Chrome browser.
Compensating Controls: Ensure that browser-based security policies are enforced and utilize endpoint detection and response (EDR) solutions to identify anomalous behavior originating from the browser renderer process.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical security risk that necessitates immediate attention. Organizations should prioritize patching all Chrome installations to the latest stable version to neutralize the threat of sandbox escape and potential system-level compromise.