Junglewise Threat Intelligence

CVE-2026-17770: Google Chrome out of bounds read in Media on macOS

CVE-2026-17770 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for macOS could allow a remote attacker to bypass security protections. By convincing a user to visit a specially crafted website, an attacker who has already gained limited control over the browser's content rendering process could escape the 'sandbox'—a security layer designed to isolate the browser from the rest of the computer. This could potentially lead to unauthorized access to the underlying operating system and user data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Media component of Google Chrome on macOS. The flaw can be triggered by a remote attacker who has already compromised the renderer process, typically via a malicious HTML page. By exploiting this memory safety issue, the attacker may be able to achieve a sandbox escape, gaining elevated privileges on the host system. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Mac.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats