Junglewise Threat Intelligence

CVE-2026-17809: Google Chrome improper input validation in Extensions sandbox escape

CVE-2026-17809 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security vulnerability in its Extensions component. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the browser's security sandbox. If successful, this could allow the attacker to gain unauthorized access to the underlying operating system or user data.

Technical details

A vulnerability classified as Improper Input Validation (CWE-20) exists in the Extensions component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be leveraged by a remote attacker. A precondition for this exploit is that the attacker must have already compromised the renderer process (e.g., via a separate vulnerability). By utilizing a specially crafted HTML page, the attacker can potentially achieve a sandbox escape, moving from the restricted renderer environment to the more privileged browser process or host system. This issue was addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats