Junglewise Threat Intelligence

CVE-2026-17701: Google Chrome ANGLE out-of-bounds read sandbox escape

CVE-2026-17701 · Severity: info · CVSS 8.8 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for Mac could allow a malicious website to break out of the browser's security sandbox. This sandbox is designed to isolate web pages from the rest of the computer to prevent unauthorized access to files or system settings. If exploited, an attacker who has already gained limited control over a browser process could potentially gain broader access to the underlying operating system.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for macOS. The flaw stems from insufficient validation of untrusted input when processing graphics data. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. If the attacker has already compromised the renderer process, they can leverage this vulnerability to bypass sandbox restrictions and potentially execute code with the privileges of the user on the host operating system. The issue is resolved in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-29: disclosed: Reported to Chrome security team
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats