CVE-2026-17744

7.1

Google · Chrome

An inappropriate implementation in the Google Chrome File Input component on Linux allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A high-severity sandbox escape vulnerability exists in Google Chrome on Linux that could allow a remote attacker to compromise the browser environment.

Vulnerability

This is an inappropriate implementation flaw within the File Input handler on Linux systems. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page, potentially leading to a sandbox escape.

Business impact

The ability to escape the browser sandbox represents a significant security failure, as the sandbox is the primary defense mechanism isolating web content from the underlying operating system. A successful exploit could grant an attacker elevated access to the host machine, potentially leading to unauthorized data access, system compromise, or further lateral movement within the network. Although the CVSS score of 7.1 denotes high severity, the risk is further elevated by the potential for full system control if the sandbox is bypassed.

Remediation

Immediate Action: Update Google Chrome on all Linux installations to version 151.0.7922.72 or later immediately.

Proactive Monitoring: Monitor system logs for unusual browser process behavior or unexpected file access patterns originating from the Chrome application environment.

Compensating Controls: Ensure that users are educated on the risks of interacting with untrusted or suspicious websites, as the exploit requires user interaction to initiate the attack sequence.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of sandbox escapes, organizations must prioritize patching all Linux-based instances of Google Chrome. Administrators should verify that all endpoints have successfully updated to the latest stable release to eliminate the risk of remote code execution or host system compromise associated with this vulnerability.

More Google CVEs

Sources