Junglewise Threat Intelligence

CVE-2026-17699: Google Chrome use after free in Views

CVE-2026-17699 · Severity: info · CVSS 8.8 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's interface component could allow a local attacker to bypass the browser's security sandbox. By tricking a user into opening a malicious file, an attacker could potentially gain unauthorized access to the underlying operating system. This could lead to the theft of sensitive data or the installation of malicious software outside of the browser's restricted environment.

Technical details

A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing a local attacker to exploit the memory corruption via a specifically crafted malicious file. Successful exploitation can lead to a sandbox escape, granting the attacker the ability to execute arbitrary code with the privileges of the user on the host operating system. The issue is resolved in Chrome version 151.0.7922.72 and later.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-29: disclosed: Reported to Chrome by Google internal researchers
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats