CVE-2026-17691

9.6

Google · Chrome

An out of bounds write vulnerability in the ANGLE graphics library of Google Chrome for Windows allows a remote attacker to achieve sandbox escape via a crafted HTML page.

Executive summary

A critical out of bounds write vulnerability in Google Chrome for Windows enables remote attackers to escape the browser sandbox, posing a severe risk of system compromise.

Vulnerability

The flaw exists within the ANGLE graphics component, where an out of bounds write (CWE-787) can be triggered by an unauthenticated remote attacker using a specially crafted HTML page. Successful exploitation requires user interaction to visit the malicious site, but it results in a sandbox escape that bypasses browser security boundaries.

Business impact

The potential for a sandbox escape represents a critical security failure, as it allows attackers to transition from browser-based execution to operating system level access. With a CVSS score of 9.6, this vulnerability facilitates full system compromise, data exfiltration, or the installation of persistent malware. Organizations must treat this as a high priority threat to workstation integrity and enterprise network security.

Remediation

Immediate Action: Update all instances of Google Chrome for Windows to version 151.0.7922.72 or later immediately to incorporate the vendor-supplied security patch.

Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected child processes spawning from the Chrome rendering engine.

Compensating Controls: While browser-specific, ensure robust endpoint detection and response (EDR) solutions are active to identify and block unauthorized system modifications that occur after a potential sandbox escape.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical severity and the nature of sandbox escape vulnerabilities, immediate patching is required to prevent potential remote code execution at the operating system level. IT administrators should prioritize this update across all corporate Windows endpoints to ensure the browser environment remains secure against this memory corruption flaw.

More Google CVEs

Sources