CVE-2026-17692
9.6Google · Chrome
A use after free vulnerability in Google Chrome DataTransfer on Windows allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome for Windows enables remote attackers to escape the browser sandbox and potentially execute arbitrary code.
Vulnerability
This is a use after free vulnerability (CWE-416) within the DataTransfer component of the Google Chrome browser. An unauthenticated remote attacker can trigger this flaw by enticing a user to navigate to a crafted HTML page, which may subsequently result in a sandbox escape.
Business impact
The vulnerability carries a CVSS score of 9.6, indicating a critical risk to organizational security. A successful sandbox escape bypasses the primary security boundary of the browser, potentially allowing an attacker to gain unauthorized access to the underlying operating system. This could lead to full system compromise, data exfiltration, or the deployment of persistent malware within the user environment.
Remediation
Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process execution patterns following web navigation.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to monitor for suspicious child processes spawned by browser-related services.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the critical CVSS severity and the potential for sandbox escape, organizations must prioritize the deployment of the Google Chrome update across all Windows workstations. Failure to patch this vulnerability leaves endpoints exposed to remote code execution risks, which can be triggered simply by users visiting a compromised or malicious website. Swift remediation is essential to maintain the integrity of the browser environment.