Junglewise Threat Intelligence

CVE-2026-17687: Google Chrome type confusion in ANGLE

CVE-2026-17687 · Severity: info · CVSS 8.8 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics engine (ANGLE) could allow a malicious website to break out of the browser's security sandbox. If successful, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying operating system and user data.

Technical details

A type confusion vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser accesses a resource using an incompatible type (CWE-843). A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. If the attacker has already achieved code execution within the sandboxed renderer process, this vulnerability can be leveraged to perform a sandbox escape, potentially leading to full system compromise. The issue is resolved in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-27: other: Reported to Google
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats