Junglewise Threat Intelligence

CVE-2026-17894: Google Chrome Use After Free in Views on Linux

CVE-2026-17894 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome for Linux within the 'Views' component, which handles the browser's user interface elements. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. Successful exploitation could lead to memory corruption, potentially allowing the attacker to crash the browser or execute unauthorized code on the user's system.

Technical details

A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome for Linux. The flaw is triggered when the browser incorrectly manages memory for UI elements after they have been freed, leading to heap corruption. A remote attacker can exploit this by hosting a malicious HTML page that, when rendered by a vulnerable browser version, triggers the memory error. This can result in a browser crash or potentially arbitrary code execution within the context of the browser process. The issue is resolved in version 151.0.7922.72 and later.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released the stable channel update fixing the issue.
  • 2026-07-30: disclosed: CVE published in the NVD dataset.

References

Related threats