Junglewise Threat Intelligence

CVE-2026-17956: Google Chrome arbitrary code execution in Scheduling

CVE-2026-17956 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its scheduling component. A remote attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could execute unauthorized code within the browser's security sandbox, potentially leading to further exploitation or instability of the application.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in the Scheduling component of Google Chrome. The flaw allows a remote, unauthenticated attacker to achieve arbitrary code execution (ACE) within the renderer process sandbox. The attack vector requires a victim to navigate to a malicious or compromised web page containing specially crafted HTML. While the impact is limited to the sandbox environment, such vulnerabilities are often chained with sandbox escapes to compromise the underlying host system. Google has addressed this issue in version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats