Junglewise Threat Intelligence

CVE-2026-17888: Google Chrome improper input validation in WebUI

CVE-2026-17888 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contains a security vulnerability in its internal WebUI component. A remote attacker could exploit this flaw to bypass the browser's security sandbox, which is designed to isolate web pages from the rest of the computer. If successful, this could allow malicious websites to gain unauthorized access to the underlying operating system or user data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebUI component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be triggered by a remote attacker via malicious network traffic. Successful exploitation could allow an attacker to perform a sandbox escape, potentially leading to arbitrary code execution outside of the browser's restricted environment. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for desktop
  • 2026-07-30: disclosed: NVD publication date

References

Related threats