CVE-2026-17723

8.3

Google · Chrome

A use after free vulnerability in the Media component of Google Chrome on Windows allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome for Windows allows remote attackers to escape the browser sandbox and execute arbitrary code.

Vulnerability

This vulnerability is a use after free error within the Media component that can be triggered by a remote attacker. Successful exploitation requires the attacker to have already compromised the renderer process and necessitates user interaction, such as visiting a crafted HTML page.

Business impact

The ability to escape the browser sandbox poses a significant risk to organizational endpoints, as it allows attackers to bypass core security boundaries designed to protect the host operating system. With a CVSS score of 8.3, this vulnerability carries a high risk of total system compromise, potentially leading to unauthorized data exfiltration, lateral movement within the network, and complete loss of system integrity.

Remediation

Immediate Action: Update all installations of Google Chrome on Windows to version 151.0.7922.72 or later immediately to apply the vendor-provided security patches.

Proactive Monitoring: Monitor endpoint logs for unusual browser activity, unexpected process creation spawned by the browser, or signs of renderer process instability.

Compensating Controls: Ensure that endpoint protection software is fully updated to detect and block malicious payloads associated with browser-based exploitation attempts, and enforce browser security policies that restrict high-risk media features where possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of a sandbox escape vulnerability and the widespread use of the Google Chrome browser, organizations should prioritize this update across all managed Windows workstations. Failure to patch allows attackers to escalate privileges from a compromised web session to the underlying operating system, significantly increasing the impact of a successful browser-based attack.

More Google CVEs

Sources