Junglewise Threat Intelligence

CVE-2026-17711: Google Chrome race condition in Downloads sandbox escape

CVE-2026-17711 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for macOS that could allow a malicious website to break out of the browser's security sandbox. This occurs due to a timing issue in how the browser handles file downloads. If exploited, an attacker who has already gained limited control over a browser tab could potentially gain broader access to the underlying operating system, compromising user data and system integrity.

Technical details

A race condition (CWE-362) exists in the Downloads component of Google Chrome for macOS. The vulnerability allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate privileges and escape the Chrome sandbox. This is achieved by exploiting improper synchronization during download operations via a specially crafted HTML page. The issue is resolved in Google Chrome version 151.0.7922.72 for Mac.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-06-04: disclosed: Reported to Google internally
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats