CVE-2026-17924
9.6Google · Chrome
A use after free vulnerability in the DNS component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows remote attackers to bypass the sandbox, posing a severe risk to system integrity and data confidentiality.
Vulnerability
This vulnerability is a use after free flaw in the DNS handling logic of the Chrome browser. An unauthenticated remote attacker who has already compromised the renderer process can leverage this flaw to escape the browser sandbox and execute arbitrary code.
Business impact
The exploitation of this vulnerability results in a complete sandbox escape, granting an attacker the ability to perform operations outside the browser environment with the privileges of the user. Given the CVSS score of 9.6, this flaw presents a critical risk that could lead to full system compromise, unauthorized data exfiltration, and persistent malware installation.
Remediation
Immediate Action: Update all Google Chrome installations to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or attempts to access restricted system files originating from the browser process.
Compensating Controls: While no direct virtual patch exists, ensuring that users operate with the principle of least privilege can limit the potential impact of a successful sandbox escape.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Organizations should prioritize the deployment of the latest Chrome update across all endpoints. Because this vulnerability facilitates a sandbox escape, it is a high priority target for advanced persistent threats, and failure to patch promptly exposes the environment to significant risk of total system compromise.