CVE-2026-17768
9.6Google · Chrome
A sandbox escape vulnerability exists in Google Chrome due to insufficient validation of untrusted input within WebSockets, allowing a remote attacker to compromise the browser renderer process.
Executive summary
Google Chrome versions prior to 151.0.7922.72 are vulnerable to a critical sandbox escape flaw that could allow a remote attacker to gain significant control over the host system.
Vulnerability
This vulnerability involves improper input validation in the WebSocket component, which can be leveraged by a remote attacker who has already compromised the renderer process to escape the browser sandbox. The attack is unauthenticated and requires user interaction, typically through a crafted HTML page.
Business impact
The ability to escape the browser sandbox allows an attacker to transition from a limited browser process compromise to arbitrary code execution on the underlying host operating system. Given the CVSS score of 9.6, the potential for full system compromise, data theft, and persistent malware installation presents an extreme risk to organizational security and endpoint integrity.
Remediation
Immediate Action: Update all instances of Google Chrome to version 151.0.7922.72 or later immediately to apply the necessary input validation patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning activities originating from the Chrome browser or its child processes.
Compensating Controls: Ensure that browser-based security policies are enforced and utilize endpoint detection and response (EDR) solutions to identify and block unauthorized system calls originating from the browser environment.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a critical threat to desktop environments and should be prioritized for immediate remediation. Given the severity of sandbox escapes, organizations must ensure that all browser instances are updated to the patched version across the enterprise to prevent potential host-level exploitation.