Junglewise Threat Intelligence

CVE-2026-17861: Google Chrome privilege escalation in Updater

CVE-2026-17861 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome update component could allow a local attacker to gain elevated system privileges. By using a specially crafted file, an attacker who already has limited access to a computer could take full control of the operating system. This could lead to unauthorized access to sensitive data, the installation of malicious software, or the disruption of business operations.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Google Chrome Updater. The flaw stems from insufficient validation of untrusted input when processing files, which can be leveraged by a local attacker to escalate privileges to the OS level. The attack requires local access to the target machine and the ability to provide a malicious file to the updater component. Successful exploitation allows an attacker to bypass security boundaries and execute code with higher privileges than originally granted. The issue is resolved in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats