Junglewise Threat Intelligence

CVE-2026-17688: Google Chrome use after free in Input

CVE-2026-17688 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's input handling component. If a user visits a specially crafted malicious website, an attacker who has already partially compromised the browser's rendering process could bypass security boundaries (the sandbox) that normally keep web content isolated from the rest of the computer. This could lead to unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Input component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of input events. An attacker can exploit this by enticing a user to visit a malicious HTML page. A successful exploit requires the attacker to have already achieved code execution within the sandboxed renderer process; from there, the UAF can be leveraged to perform a sandbox escape to the browser process or operating system. Google addressed this issue in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-27: disclosed: Reported to Chromium project
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats