Junglewise Threat Intelligence

CVE-2026-17738: Google Chrome improper input validation in Payments sandbox escape

CVE-2026-17738 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contains a security vulnerability in its Payments component. If an attacker has already compromised the browser's rendering process, they could use this flaw to break out of the browser's security sandbox. This could allow them to gain broader access to the underlying operating system and user data beyond what is normally permitted for a web page.

Technical details

A vulnerability classified as improper input validation (CWE-20) exists in the Payments component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By leveraging a specially crafted HTML page, the attacker can escape the process isolation layer to interact with the host system. This issue was addressed in Google Chrome version 151.0.7922.72. The vulnerability was assigned a Medium severity rating by the Chromium security team.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats