CVE-2026-17708
9.6Google · Chrome
A use after free vulnerability in the Google Chrome Audio component allows a remote attacker to perform a sandbox escape via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows unauthenticated remote attackers to escape the browser sandbox, posing a severe risk of system compromise.
Vulnerability
This is a use after free vulnerability located in the Audio component of the Chrome browser. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a crafted HTML page, potentially leading to a sandbox escape and arbitrary code execution within the context of the host system.
Business impact
The vulnerability carries a CVSS score of 9.6, indicating a critical risk to business operations. Successful exploitation allows an attacker to bypass critical security boundaries, potentially leading to full system compromise, data theft, and unauthorized access to internal resources. The ability to escape the sandbox environment significantly increases the impact by allowing the attacker to move beyond the browser process to the underlying operating system.
Remediation
Immediate Action: Update all instances of Google Chrome to version 151.0.7922.72 or later to incorporate the necessary security patches.
Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected process spawns originating from the Chrome renderer process.
Compensating Controls: Ensure that the browser is running with the latest security features enabled and consider utilizing endpoint protection solutions that can detect unauthorized attempts to escape the browser sandbox.
Exploitation status
Public Exploit Available: No — exploit_available is false.
Analyst recommendation
Given the critical CVSS severity and the potential for complete sandbox bypass, this vulnerability represents a high-priority risk. Organizations must prioritize the deployment of the vendor-provided update across all managed endpoints immediately to prevent potential exploitation of this memory corruption flaw.