Junglewise Threat Intelligence

CVE-2026-17704: Google Chrome use after free in ANGLE

CVE-2026-17704 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering. A remote attacker who has already compromised the browser's rendering process could use this flaw to escape the security sandbox. This could allow the attacker to gain broader access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is reachable via a crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this memory corruption issue to perform a sandbox escape. This vulnerability was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Google classifies this as a High severity issue.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-06-02: disclosed: Reported by Google internal researchers
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats