Junglewise Threat Intelligence

CVE-2026-17898: Google Chrome use after free in DevTools

CVE-2026-17898 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contains a security vulnerability in its developer tools (DevTools). If a user is tricked into installing a malicious browser extension, an attacker could execute unauthorized code within the browser's restricted security sandbox. While the impact is limited to the sandbox, it represents a breakdown of the browser's internal security boundaries.

Technical details

A use-after-free (UAF) vulnerability exists in the DevTools component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the execution of a specially crafted Chrome Extension. To exploit this, an attacker must first persuade a user to install a malicious extension. Successful exploitation allows for arbitrary code execution within the browser's sandbox environment. The issue is addressed in Google Chrome version 151.0.7922.72 and later.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-07-30: disclosed: NVD publication date.

References

Related threats