Junglewise Threat Intelligence

CVE-2026-17708: Google Chrome use after free in Audio

CVE-2026-17708 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's audio component that could allow an attacker to bypass the browser's security sandbox. This sandbox is designed to prevent malicious websites from accessing the rest of your computer. If successfully exploited, an attacker who has already compromised a browser tab could gain broader access to the underlying operating system, potentially leading to data theft or unauthorized software installation.

Technical details

A use-after-free (UAF) vulnerability exists in the Audio component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during audio processing, allowing a remote attacker to reference memory after it has been freed. To exploit this, an attacker must first compromise the renderer process (typically via a separate vulnerability). Once the renderer is compromised, the attacker can use a specially crafted HTML page to trigger the UAF in the browser process, potentially achieving a sandbox escape and executing arbitrary code with the privileges of the browser. This issue is addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-06-04: disclosed: Reported by Google internally
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats