Junglewise Threat Intelligence

CVE-2026-17660: Google Chrome improper input validation in Network component

CVE-2026-17660 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its networking component could allow a malicious website to bypass the browser's security sandbox if the attacker has already gained partial control over the browser's rendering process. This could lead to unauthorized access to the underlying operating system and the user's private data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Network component of Google Chrome. A remote attacker who has already compromised the renderer process can exploit this flaw via a specially crafted HTML page to perform a sandbox escape. This allows the attacker to break out of the restricted environment intended to isolate web content from the rest of the system. The vulnerability is fixed in version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-03-29: disclosed: Reported to Chromium project
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats