Junglewise Threat Intelligence

CVE-2026-17718: Google Chrome use after free in ANGLE

CVE-2026-17718 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's ANGLE component, which handles graphics processing. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data beyond the browser's normal restrictions.

Technical details

A use-after-free (UAF) vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics content, specifically via a crafted HTML page. A remote, unauthenticated attacker can exploit this condition to achieve a sandbox escape, potentially leading to arbitrary code execution outside the browser's restricted environment. The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats