Junglewise Threat Intelligence

CVE-2026-17784: Google Chrome use after free in Audio on macOS

CVE-2026-17784 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome for macOS that could allow a malicious website to bypass security protections. If a user visits a specially crafted webpage, an attacker who has already partially compromised the browser's rendering process could escape the 'sandbox'—the security layer designed to keep web content isolated from the rest of the computer. This could lead to unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Audio component of Google Chrome for macOS. The flaw can be triggered via a crafted HTML page. A precondition for exploitation is that the attacker must have already compromised the renderer process. Successful exploitation allows the attacker to perform a sandbox escape, potentially gaining elevated privileges on the host system. The issue is addressed in Chrome version 151.0.7922.72 for Mac.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats