Junglewise Threat Intelligence

CVE-2026-17650: Google Chrome use after free in Compositing sandbox escape

CVE-2026-17650 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's compositing engine, which is responsible for rendering visual elements on screen. An attacker who has already compromised a browser tab's rendering process could exploit this flaw to break out of the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system and sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Compositing component of Google Chrome prior to version 151.0.7922.72. The flaw is triggered when the browser incorrectly manages memory during the rendering of complex visual content. A remote attacker who has already achieved code execution within the sandboxed renderer process can leverage this UAF to perform a sandbox escape. This is achieved by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code outside the browser's security boundaries on the host system. Google has addressed this in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-18: disclosed: Reported by Google internal researchers
  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats