Junglewise Threat Intelligence

CVE-2026-17924: Google Chrome use after free in DNS

CVE-2026-17924 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its DNS handling component. If a user visits a specially crafted malicious website, an attacker who has already partially compromised the browser's rendering engine could potentially bypass security protections (the 'sandbox') to gain further access to the underlying system. This could lead to unauthorized access to local files or broader system control.

Technical details

A use-after-free (UAF) vulnerability exists in the DNS component of Google Chrome prior to version 151.0.7922.72. The flaw is triggered when the browser incorrectly manages memory during DNS resolution tasks. An attacker who has already achieved code execution within a compromised renderer process can exploit this memory corruption to escape the Chrome sandbox by enticing a user to visit a malicious HTML page. This vulnerability is tracked as CWE-416. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update 151.0.7922.72 released.
  • 2026-07-30: disclosed: NVD publication date.

References

Related threats