Junglewise Threat Intelligence

CVE-2026-17856: Google Chrome Network sandbox escape on Mac

CVE-2026-17856 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Mac that could allow a malicious website to bypass the browser's security sandbox. The sandbox is a critical defense layer designed to prevent malicious code from escaping the browser and interacting with the rest of the computer. If successfully exploited, an attacker who has already gained control of a browser tab could potentially access or modify files and data on the user's system.

Technical details

A sandbox escape vulnerability exists in the Network component of Google Chrome for macOS. The flaw stems from an inappropriate implementation that allows a compromised renderer process to break out of its restricted environment. To exploit this, an attacker must first achieve code execution within a renderer process (typically via a separate vulnerability) and then lure a user to a specially crafted HTML page. A successful exploit allows the attacker to bypass the Chromium sandbox, potentially leading to unauthorized access to the underlying operating system. This issue was addressed in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats