CVE-2026-17688

9.6

Google · Chrome

A use after free vulnerability in the Google Chrome Input component allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to escape the browser sandbox and execute arbitrary code.

Vulnerability

This is a use after free vulnerability (CWE-416) occurring within the Input component of the browser. It allows an unauthenticated remote attacker who has already compromised the renderer process to trigger a memory corruption flaw, leading to a sandbox escape.

Business impact

The ability to escape the browser sandbox represents a significant security failure that effectively bypasses the primary isolation mechanism protecting the underlying operating system. With a CVSS score of 9.6, this flaw poses a severe risk of full system compromise, unauthorized data access, and persistent malware installation. Organizations should treat this as a high priority threat to workstation and server integrity.

Remediation

Immediate Action: Update all Google Chrome instances to version 151.0.7922.72 or later immediately to incorporate the security patches provided by the vendor.

Proactive Monitoring: Review endpoint security logs for unusual browser crashes or unexpected process behavior originating from the Chrome renderer process.

Compensating Controls: Ensure that modern browser-based security features, such as Site Isolation, are enabled, and deploy endpoint detection and response (EDR) solutions to monitor for unauthorized process elevation attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical CVSS severity and the potential for sandbox escape, organizations must prioritize the rapid deployment of the latest Chrome update across all managed environments. Failure to patch this vulnerability leaves endpoints susceptible to remote code execution and full system compromise by sophisticated threat actors.

More Google CVEs

Sources