CVE-2026-17692

9.6

Google · Chrome

A use after free vulnerability in Google Chrome DataTransfer on Windows allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome for Windows enables remote attackers to escape the browser sandbox and potentially execute arbitrary code.

Vulnerability

This is a use after free vulnerability (CWE-416) within the DataTransfer component of the Google Chrome browser. An unauthenticated remote attacker can trigger this flaw by enticing a user to navigate to a crafted HTML page, which may subsequently result in a sandbox escape.

Business impact

The vulnerability carries a CVSS score of 9.6, indicating a critical risk to organizational security. A successful sandbox escape bypasses the primary security boundary of the browser, potentially allowing an attacker to gain unauthorized access to the underlying operating system. This could lead to full system compromise, data exfiltration, or the deployment of persistent malware within the user environment.

Remediation

Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process execution patterns following web navigation.

Compensating Controls: Deploy endpoint detection and response (EDR) solutions to monitor for suspicious child processes spawned by browser-related services.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the critical CVSS severity and the potential for sandbox escape, organizations must prioritize the deployment of the Google Chrome update across all Windows workstations. Failure to patch this vulnerability leaves endpoints exposed to remote code execution risks, which can be triggered simply by users visiting a compromised or malicious website. Swift remediation is essential to maintain the integrity of the browser environment.

More Google CVEs

Sources