Junglewise Threat Intelligence

CVE-2026-17935: Google Chrome heap buffer overflow in Codecs

CVE-2026-17935 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, is affected by a security vulnerability in its media processing components. An attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could execute unauthorized code within the browser's restricted environment, potentially leading to further attacks or instability.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Codecs component of Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, allowing a remote attacker to achieve arbitrary code execution within the renderer sandbox. While the impact is limited by the sandbox, it represents a significant memory safety issue. The vulnerability was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats