Junglewise Threat Intelligence

CVE-2026-17653: Google Chrome Skia use after free sandbox escape

CVE-2026-17653 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's Skia graphics engine. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox and gain broader access to the underlying system. Users should update to version 151.0.7922.72 or later to protect their data and operations from potential unauthorized access.

Technical details

This vulnerability is a use-after-free (UAF) class flaw (CWE-416) located within the Skia graphics library as integrated into Google Chrome. The vulnerability is reachable via a crafted HTML page. A successful exploit requires the attacker to have already achieved code execution within the renderer process (e.g., via a separate vulnerability). Once the renderer is compromised, this UAF can be leveraged to bypass the Chromium sandbox, potentially leading to full system compromise. The issue was addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-06-05: disclosed: Reported to Google
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats