Junglewise Threat Intelligence

CVE-2026-17745: Google Chrome out of bounds read in Skia

CVE-2026-17745 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a remote attacker to bypass security protections. If a user visits a specially crafted website, an attacker who has already compromised the browser's rendering process could potentially escape the security 'sandbox' that normally isolates the browser from the rest of the computer. This could lead to further unauthorized access to the underlying system.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Skia graphics library component of Google Chrome. The flaw is reachable via a crafted HTML page. A remote attacker who has already achieved code execution within a compromised renderer process could exploit this memory corruption to facilitate a sandbox escape. The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats