Junglewise Threat Intelligence

CVE-2026-17712: Google Chrome Race Condition in Skia

CVE-2026-17712 · Severity: info · CVSS 8.8 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics engine, Skia, could allow a malicious website to execute unauthorized code on a user's Mac. While the attack is limited to the browser's security sandbox, it could lead to data theft or further system compromise if combined with other flaws.

Technical details

A race condition (CWE-362) exists in the Skia graphics library component of Google Chrome on macOS. The vulnerability is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to achieve arbitrary code execution (ACE) within the renderer process sandbox. This flaw was identified in versions prior to 151.0.7922.72. Users are advised to update to the latest stable channel release to mitigate this risk.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-06-05: disclosed: Reported to Chromium by Google internal researchers
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats