Junglewise Threat Intelligence

CVE-2026-17863: Google Chrome privilege escalation in Browser on Windows

CVE-2026-17863 · Severity: info · CVSS 6.1 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome browser on Windows could allow a local attacker to gain elevated privileges on a user's system. By tricking a user into interacting with a malicious file, an attacker could bypass security restrictions to perform actions with higher authority than normally permitted. This could lead to unauthorized system changes or access to sensitive data.

Technical details

An inappropriate implementation in the Browser component of Google Chrome on Windows allowed for local privilege escalation. The vulnerability is triggered when a local attacker provides a specially crafted malicious file that the browser processes incorrectly. While specific root cause details are restricted, the flaw enables an attacker to bypass standard permission boundaries. This issue affects Windows installations prior to version 151.0.7922.72. Users are advised to update to the latest stable channel release to mitigate this risk.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released a stable channel update addressing the issue.
  • 2026-07-30: disclosed: CVE published in the NVD dataset.

References

Related threats