CVE-2026-17704

9.6

Google · Chrome

A use after free vulnerability in the ANGLE component of Google Chrome allows a remote attacker to achieve sandbox escape via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome enables remote attackers to escape the browser sandbox and potentially execute arbitrary code on the underlying system.

Vulnerability

This flaw is a use after free vulnerability (CWE-416) within the ANGLE graphics engine component. A remote, unauthenticated attacker can exploit this via a specifically crafted HTML page to trigger a sandbox escape after compromising the renderer process.

Business impact

The ability to escape the browser sandbox represents a significant security failure that undermines the isolation model of the application. Given the CVSS score of 9.6, this vulnerability poses a severe risk of unauthorized system access, data exfiltration, or complete host compromise. Organizations should prioritize patching to prevent attackers from leveraging this flaw to pivot from a browser-based compromise to full system control.

Remediation

Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for anomalous browser behavior or unexpected process execution patterns originating from the Google Chrome renderer process.

Compensating Controls: Utilize endpoint protection platforms that can detect and block malicious web content or prevent unauthorized child process spawning from browser applications.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for full system compromise via sandbox escape, all instances of Google Chrome must be updated to the patched version as a matter of high priority. IT administrators should verify version compliance across all managed endpoints to ensure the update has been applied successfully.

More Google CVEs

Sources