Junglewise Threat Intelligence

CVE-2026-17768: Google Chrome sandbox escape in WebSockets

CVE-2026-17768 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebSocket component could allow a remote attacker who has already compromised a website's rendering process to break out of the browser's security sandbox. If successful, this could allow the attacker to gain broader access to the underlying operating system and user data beyond the restricted browser environment.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebSocket implementation of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By utilizing a specially crafted HTML page, the attacker can exploit the insufficient validation of untrusted input to escape the renderer sandbox. This vulnerability was addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats