Junglewise Threat Intelligence

CVE-2026-17671: Google Chrome sandbox escape in ANGLE

CVE-2026-17671 · Severity: info · CVSS 8.8 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's graphics layer (ANGLE) that could allow an attacker to break out of the browser's security sandbox. This occurs if a user visits a specially crafted malicious website and the attacker has already compromised the browser's rendering process. A successful exploit could allow the attacker to gain broader access to the underlying operating system, potentially leading to data theft or full system compromise.

Technical details

An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to bypass sandbox restrictions. By enticing a user to visit a malicious HTML page, the attacker can exploit this insufficient validation to escape the sandbox and execute arbitrary code with the privileges of the browser process. This vulnerability was fixed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-14: other: Reported to Google
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats