Junglewise Threat Intelligence

CVE-2026-17886: Google Chrome use after free in Enterprise

CVE-2026-17886 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Enterprise component that could allow a malicious website to corrupt the browser's memory. If a user visits a specially crafted webpage, an attacker could potentially cause the browser to crash or execute unauthorized actions. This issue affects users on Windows, Mac, and Linux systems running older versions of the browser.

Technical details

A use-after-free (UAF) vulnerability exists in the Enterprise component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory pointers after an object has been deleted, leading to heap corruption. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation could lead to arbitrary code execution within the browser's sandbox or a denial-of-service (browser crash). The vulnerability is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats