CVE-2026-17697
9.6Google · Chrome
A type confusion vulnerability in the ANGLE graphics engine allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Executive summary
A critical type confusion vulnerability in Google Chrome, identified as CVE-2026-17697, enables remote attackers to escape the browser sandbox and potentially execute arbitrary code.
Vulnerability
This vulnerability involves a type confusion flaw within the ANGLE graphics component of the Chromium engine. An unauthenticated remote attacker can trigger this issue by enticing a user to visit a specially crafted HTML page, leading to a sandbox escape.
Business impact
The ability to escape the browser sandbox represents a significant security breach, as it bypasses the primary defensive boundary between the browser and the underlying operating system. Given the CVSS score of 9.6, this vulnerability carries a critical severity rating, potentially leading to full system compromise, data theft, or the installation of persistent malware on the host machine.
Remediation
Immediate Action: Update all installations of Google Chrome to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint detection and response (EDR) logs for suspicious browser process behavior, such as unauthorized shell spawning or unexpected network connections originating from the Chrome process.
Compensating Controls: Ensure that browser security features are enabled and utilize endpoint protection solutions that can detect common exploitation patterns associated with memory corruption and sandbox escapes.
Exploitation status
Public Exploit Available: No confirmed public exploit is currently available.
Analyst recommendation
Due to the critical nature of this vulnerability and its potential for full system compromise, organizations should prioritize the deployment of the Google Chrome update across all workstations. Users should be advised to restart their browsers to ensure the update is fully applied, and administrators should verify that all managed systems are running the patched version.