Junglewise Threat Intelligence

CVE-2026-17750: Google Chrome use after free in ANGLE

CVE-2026-17750 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's graphics engine (ANGLE) that could allow a malicious website to bypass security restrictions. By tricking a user into visiting a specially crafted webpage, an attacker could potentially escape the browser's security sandbox, which is designed to keep web content isolated from the rest of the computer. This could lead to unauthorized access to the underlying operating system or user data.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the processing of complex graphics instructions. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page that, when rendered by a vulnerable browser, triggers the memory corruption. Successful exploitation could allow the attacker to achieve a sandbox escape, potentially leading to arbitrary code execution on the host system. The issue is resolved in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats