Junglewise Threat Intelligence

CVE-2026-17758: Google Chrome heap buffer overflow in Dawn

CVE-2026-17758 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's Dawn component, which handles graphics processing. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to bypass the browser's security sandbox. If successful, this could lead to unauthorized access to the underlying operating system or user data.

Technical details

A heap-based buffer overflow (CWE-122) exists in Dawn, the WebGPU implementation in Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to overflow a buffer on the heap. This memory corruption can be leveraged to achieve a sandbox escape, potentially leading to arbitrary code execution outside the restricted browser environment. The issue was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats