CVE-2026-17803

9.6

Google · Chrome

A sandbox escape vulnerability exists in Google Chrome due to insufficient validation of untrusted input within the Save to Drive feature when processing crafted PDF files.

Executive summary

A critical sandbox escape vulnerability in Google Chrome allows remote attackers to bypass security boundaries, necessitating an immediate update to version 151.0.7922.72 or later.

Vulnerability

The flaw is caused by insufficient validation of untrusted input (CWE-20) within the Save to Drive component. An unauthenticated remote attacker who has already compromised the renderer process can leverage this flaw via a crafted PDF file to achieve a sandbox escape.

Business impact

The vulnerability carries a CVSS score of 9.6, indicating a critical severity level. A successful exploit allows an attacker to break out of the browser sandbox, potentially leading to arbitrary code execution on the underlying host system. This poses a severe risk of data exfiltration, unauthorized system access, and complete compromise of the affected workstation.

Remediation

Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to apply the necessary input validation fixes.

Proactive Monitoring: Monitor endpoint detection and response logs for unusual child processes spawning from the Chrome renderer or unexpected file system modifications related to PDF handling.

Compensating Controls: Ensure that the browser is running with the latest security baseline configurations and utilize endpoint protection software to detect and block malicious PDF execution patterns.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for a full sandbox escape, this vulnerability represents a significant threat to organizational security. Administrators must prioritize the deployment of the latest Chrome update across all managed devices. Failure to patch may leave systems susceptible to privilege escalation if a secondary renderer-level exploit is utilized by an attacker.

More Google CVEs

Sources