Junglewise Threat Intelligence

CVE-2026-17716: Google Chrome use after free in Updater privilege escalation

CVE-2026-17716 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the update component of Google Chrome for macOS. This flaw could allow a local attacker—someone who already has limited access to the computer—to gain higher-level system permissions. If exploited, this could lead to a full compromise of the device, allowing unauthorized access to sensitive data or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) was identified in the Updater component of Google Chrome for macOS. The flaw is triggered when the application attempts to use memory after it has been freed, which can be manipulated by a local attacker via malicious network traffic to achieve privilege escalation. The vulnerability affects versions prior to 151.0.7922.72. Google has addressed this issue in the stable channel update 151.0.7922.72 for Mac.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats