Junglewise Threat Intelligence

CVE-2026-17719: Google Chrome use after free in Input

CVE-2026-17719 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, is affected by a security vulnerability in its input handling component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code on the user's computer. While the exploit is limited to the browser's security sandbox, it could be used as part of a larger attack to compromise the system or access sensitive user data.

Technical details

A use-after-free vulnerability exists in the Input component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of specific input events, allowing a remote attacker to achieve arbitrary code execution within the renderer process sandbox. Exploitation requires a victim to navigate to a malicious HTML page. This vulnerability is addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats