Junglewise Threat Intelligence

CVE-2026-17922: Google Chrome inappropriate implementation in Enterprise

CVE-2026-17922 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the Enterprise component of Google Chrome, a widely used web browser. An attacker could potentially execute unauthorized code on a user's computer if the user visits a specially crafted website. This could lead to a compromise of the user's local system, data theft, or unauthorized access to corporate resources.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists within the Enterprise component of Google Chrome. The flaw allows a remote, unauthenticated attacker to achieve arbitrary code execution (RCE) by enticing a user to visit a maliciously crafted HTML page. While the impact is code execution, Chromium has assigned this a 'Low' severity rating, likely due to specific preconditions or sandbox limitations not fully detailed in the public advisory. The issue is resolved in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for desktop
  • 2026-07-30: disclosed: NVD publication date

References

Related threats