CVE-2026-17699

Google · Chrome

A use after free vulnerability exists in the Views component of Google Chrome, which could allow a local attacker to execute arbitrary code.

Executive summary

Google Chrome is affected by a use after free vulnerability in the Views component that could lead to complete system compromise.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Views component. The vulnerability is triggered via local access and requires user interaction to exploit, but does not require authentication.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution on the affected machine. Given the CVSS score of 8.6, this represents a high risk to organizational security, potentially leading to unauthorized data access, system instability, or full control of the endpoint.

Remediation

Immediate Action: Update Google Chrome to version 151.0.7922.72 or later to apply the necessary security patches.

Proactive Monitoring: Review endpoint security logs for abnormal process behavior or unexpected crashes related to the Google Chrome application.

Compensating Controls: Ensure that endpoint protection software is active and configured to block unauthorized execution of malicious payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high CVSS score of 8.6 underscores the severity of this flaw. Organizations should prioritize patching all Google Chrome instances to the latest version immediately to eliminate the risk of arbitrary code execution.